Gentoo Archives: gentoo-security

From: Alexander Schreiber <als@××××××××××××.de>
To: Daniel Privratsky <dsokrates@××××××.cz>
Cc: gentoo-security@l.g.o
Subject: Re: [gentoo-security] firewall suggestions?
Date: Thu, 08 Jan 2004 18:40:12
Message-Id: 20040108182237.GC1533@mordor.angband.thangorodrim.de
In Reply to: Re: [gentoo-security] firewall suggestions? by Daniel Privratsky
1 On Thu, Jan 08, 2004 at 06:57:28PM +0100, Daniel Privratsky wrote:
2 > Wrong.
3 >
4 > 1) If you don't receive "destination unreachable" packet, you know
5 > nothing about the target host yet. This is not perfect-network world.
6 > There can be other fw/router anywhere in the way, killing this type of
7 > icmp traffic.
8 >
9 > 2) It slows scans a lot.
10
11 Only for people too stupid for doing port scans (a rare defect even
12 among script kiddies).
13
14 > You can of course do scannig in parallel, but
15 > don't be surprised, when you find yourself killed with no mercy by IDS,
16 > after matching SYN threshold. 1000+ syns/sec form IP adress to monitored
17 > system is sure ban.
18
19 Cool. Your IDS just banned the IPs of your customers mail-, web- and
20 proxy-servers. Spoofing IP adresses just to mess with such automatic
21 systems is easy.
22
23 Regards,
24 Alex.
25 --
26 "Opportunity is missed by most people because it is dressed in overalls and
27 looks like work." -- Thomas A. Edison
28
29 --
30 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] firewall suggestions? Mans Matulewicz <cybermans@××××××.nl>
Re: [gentoo-security] firewall suggestions? Daniel Privratsky <dsokrates@××××××.cz>