Anyway the dtk makes fake fingerprints that say windows.. .
Aussie wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1On Tue, 04 Apr 2000 at 20:07 +1100, Alexander Else <[EMAIL PROTECTED]> wrote:
> >The characteristics of your IP stack will give away far more
> >information than denying or rejecting packets. Check out queso, nmap,
> >etc and see what they tell you. *Any* response from your system gives
> >away information about it. You can't pretend to be a Windows box even
> >if you *can* make Linux crash at random times. The IP stacks are just
> >too distinctive.
>
> I did cover that point already (search for 'fingerprint' in a prior
> email). Here I'm going on the hope that they run fast scans across
> their ip pools, pick up some obvious 'servers' *snicker*, and maybe flag
> some likelies for further investigation. I'm hoping that my suggestions
> might avoid being tossed into the 'likely' basket.One quick question that puzzles me from the first mention of
fingerprinting, WHY would Optus be doing this? Do they prohibit you
from using the OS of your choice on their network? What other use would
they have of any fingerprint?
I would have thought that O@H would just do a port scan on known
server ports to determine firstly if they were open, then to see if
those ports were active.
Just because you can run a server, doesn't mean you do. If they want
to make that claim, ask if they've raped anyone.....after all, if
they're male they are able to rape a female....it doesn't mean they do
however. (My apologies to anyone offended by my example, no offense is
intended)
Unless O@H is going to tell you what OS you can and cannot use on
their service, they have no right to fingerprint you, a simple portscan
is sufficient to tell them if you are running servers.> firewalling policies boring?! yeah, ok. I think I've made my point
> anyway.Not at all, an effective firewall is something that a lot of people
don't know how to implement, and while I hope I have a secure one, I'm
always open to suggestions as to what others consider a secure
firewall.David Mudford
-----BEGIN PGP SIGNATURE-----
Version: PGP 6.0.2 -- QDPGP 2.60
Comment: Please verify this signature. http://www.pgpi.comiQA+AwUBOOk0BpZb9oayhFBBEQIqjACfcrupJ+abQ5cAFgDDvHZJZ33DGtkAmOIg
IEYYjck/o1JsSAcLE+4wjE4=
=q1Pd
-----END PGP SIGNATURE-----
PGP Key Block available at:
http://aussie.mine.nu/aussie/pgp_key.txt
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text
-- "Data itself isn't good nor bad, data just represents the surrounding reality. The more data we may access, the more accurate model we may create of the reality, thereby also define our actions in ways that are maximally beneficial to our aims. The net must not be restricted by moral, ethical nor legal issues prevailing in different world locations, data must flow freely." -- chip.
