1 |
On Thu, Jan 08, 2004 at 06:57:28PM +0100, Daniel Privratsky wrote: |
2 |
> Wrong. |
3 |
> |
4 |
> 1) If you don't receive "destination unreachable" packet, you know |
5 |
> nothing about the target host yet. This is not perfect-network world. |
6 |
> There can be other fw/router anywhere in the way, killing this type of |
7 |
> icmp traffic. |
8 |
> |
9 |
> 2) It slows scans a lot. |
10 |
|
11 |
Only for people too stupid for doing port scans (a rare defect even |
12 |
among script kiddies). |
13 |
|
14 |
> You can of course do scannig in parallel, but |
15 |
> don't be surprised, when you find yourself killed with no mercy by IDS, |
16 |
> after matching SYN threshold. 1000+ syns/sec form IP adress to monitored |
17 |
> system is sure ban. |
18 |
|
19 |
Cool. Your IDS just banned the IPs of your customers mail-, web- and |
20 |
proxy-servers. Spoofing IP adresses just to mess with such automatic |
21 |
systems is easy. |
22 |
|
23 |
Regards, |
24 |
Alex. |
25 |
-- |
26 |
"Opportunity is missed by most people because it is dressed in overalls and |
27 |
looks like work." -- Thomas A. Edison |
28 |
|
29 |
-- |
30 |
gentoo-security@g.o mailing list |