On Tue, Apr 04, 2000 at 04:41:25PM +1000, Alexander Else wrote:

> >What's the difference between a dropped packet and an unreachable address?
> 
> Specific to this situation where it might be considered desirable to look 
> like a standard windows 98 box, REJECTing a connection will make it appear 

This is one point where we differ.  I cannot see any advantage in looking
like a Windows box, and since this *is* a Linux list, I suspect the vast
majority agree with *me* :-)

> hah!  regardless of your intent in this thread, mine is to indicate ways 
> that you might defeat O@H's scanning software. 

I'm only suggesting people defeat Optus's scans by improving their
security generally, so that if they don't *want* to run a server, they
don't appear to be running one according to Optus simplistic rules.  I do
not, and will not, advocate violating the AUP by hiding from the scans.  
Yes, you can modify my original firewalls rules to do this, maybe even
successfully, but if you get caught, I'll have absolutely no sympathy.  
Indeed, if you're trying to violate the AUP you've agreed to, then you
deserve to get caught.

> You are going to protest to  Optus that they are the ones attacking you?

If they did actually attack one of my systems, then I would.  However, I
don't use Optus@home, and won't use them as long as the "no servers"
restriction remains, so they're unlikely to scan one of my systems.

I'm trying to help others who've *inadvertantly* been caught by Optus's
incompetent attempts at detecting servers, and also securing their
machines against simple port scans.

> I don't care what an attacker thinks ordinarily.  In this case I want to 
> hide amongst the unwashed masses, not stand up and say "lookey here, I've 
> got a firewall!".  That point is easily argued against, but nevertheless 

I don't want to hide.  I'm happy to show that I have a firewall,
especially if it makes the script-kiddies look for an easier target.
However, I will configure my firewall to provide the absolute minimum of
information to a potential attacker, and if that includes not replying to
a packet wherever possible, then I'll do that.

> it's something that *may* be considered in the minds of those (at optus) 
> doing the scanning.

I doubt it.  The test for the presence of a server is far too simplistic
to show this level of thought.  I doubt they've really thought about it at
all.

> > > In this situation we're not just trying to block access to servers,
> > > we're trying to hide even their existence.
> >
> >No we're not.  I'm not suggesting that people hide servers.  I'm
> 
> I think that this is where we differ on our opinions of what people may 
> hope to gain from this discussion.  You're suggesting hiding, I'm 
> suggesting hiding within a crowd.

The characteristics of your IP stack will give away far more information
than denying or rejecting packets.  Check out queso, nmap, etc and see
what they tell you.  *Any* response from your system gives away
information about it.  You can't pretend to be a Windows box even if you
*can* make Linux crash at random times.  The IP stacks are just too
distinctive.

Now, I think we've discussed this topic to sufficient detail to bore the
crap out of most people.  I know there's been bugger all else list traffic
today, but I think we should keep any future discussion in private email.

If I'd realise the amount of attention this thread was going to get, I
don't know that I'd have started it ... :-)

Cheers,

John
-- 
whois [EMAIL PROTECTED]
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to