Re: Syn+Fin (Setup) And TCP RST

From: Giorgos Keramidas (keramidi@otenet.gr)
Date: 05/30/01


Date: Wed, 30 May 2001 13:52:52 +0300
From: Giorgos Keramidas <keramidi@otenet.gr>
To: Liran Dahan <lirandb@netvision.net.il>

On Wed, May 30, 2001 at 01:28:30AM +0200, Liran Dahan wrote:
> I checked the rules order, its ok...But something strange..
> I've added rule like: ipfw add 1 reset tcp from any to any 100-200 , and i
> have daemon running on port 110, i telneted it and i got connection refused
> after 2 secs..(even when i have TCP_RESTRICT_RST Enabled - Via sysctl and
> Kernel), But when i telneted the other ports (that arent running daemons -
> Closed ports), it took about 30 seconds till i got connection refused - or
> it was connection timeout (i did it from windows telnet).

Why do I have the strange feeling that you have PARANOID enabled in your
hosts.allow for telnet connections and some DNS server times out on you?

--giorgos

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: I have some questions about telnet/telnetd/libtelnet/tn3270 and why FreeBSD is different than ot
    ... ¥ I've had a license to punt this to ports for _years_. ... Rambler produced hits logged several years before; ... version of telnet. ... Things like 3270 terminals are ...
    (freebsd-questions)
  • is this real?
    ... Interesting ports on xxx.xxx.xxx.xxx: ... me, telnet online, finger talks to the whole world and so on.... ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)
  • Re: DNS problem?
    ... you should be able to telnet to all those ports from the internet. ... > is a proper firewall. ...
    (microsoft.public.windows.server.sbs)
  • Re: [SLE] worrying port scan
    ... FTP and Telnet are _not_ running on your box. ... connections to those ports. ... Many do DROP connections in to certain ... If an upstream firewall/ACL is preventing access to those ...
    (SuSE)
  • Really weird expect problem
    ... I'm working on a legacy expect script. ... At first glance it would seem that the shell is in echo or verbose mode, ... is operating telnet from a Windows 2000 machine. ... I've looked for strange environment variables. ...
    (comp.unix.programmer)