At 11:11 AM 4/4/00 +1000, you wrote:
>What's the difference between a dropped packet and an unreachable address?
Specific to this situation where it might be considered desirable to look
like a standard windows 98 box, REJECTing a connection will make it appear
that there's nothing listening on a port. DENYing will just blackhole the
packet.
>recipient, just that you haven't received a response. A reject tells you
>immediately that there's no point in continuing on that port, so you don't
>need to waste any more time on it. The more energy an attacker wastes
.....my point exactly.
>beating against your firewall, the more of their time they waste, and the
>more evidence you have to present to their ISP. Sometimes the ISP will
>enforce their AUP ...
hah! regardless of your intent in this thread, mine is to indicate ways
that you might defeat O@H's scanning software. You are going to protest to
Optus that they are the ones attacking you? Nah...
> > rejects from everything but 21 and 80 I'm going to start thinking
> something
> > is up.
>
>I don't care what you think, I just don't want you getting access to any
>of my machines. If your packets don't get to the target machine, there's
>no way you're going to be able to break in.
I don't care what an attacker thinks ordinarily. In this case I want to
hide amongst the unwashed masses, not stand up and say "lookey here, I've
got a firewall!". That point is easily argued against, but nevertheless
it's something that *may* be considered in the minds of those (at optus)
doing the scanning.
> > In this situation we're not just trying to block access to servers,
> > we're trying to hide even their existence.
>
>No we're not. I'm not suggesting that people hide servers. I'm
I think that this is where we differ on our opinions of what people may
hope to gain from this discussion. You're suggesting hiding, I'm
suggesting hiding within a crowd.
> > The more you make it look like a windows box, the better.
>
>Complete with security holes? I know, lets make it crash randomly,
>that'll fool them :-)
heh.
> > default DENY policy, but they may take that to mean that you're trying to
> > stop them scanning :)
>
>Almost. You're not trying to stop their scans, you're trying to stop
>*everyone's* scans and other attacks. It's called security.
Well thanks for the enlightenment :P
Alexander Else
http://cyberchrist.org
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text