Re: iptables REJECT types for UDP (if any)

From: Pierre Spielmann (mlists@pierre-spielmann.de)
Date: 11/22/02

  • Next message: Alexander Gran: "Re: iptables REJECT types for UDP (if any)"
    Date: Fri, 22 Nov 2002 13:17:25 +0100
    From: Pierre Spielmann <mlists@pierre-spielmann.de>
    To: focus-linux@securityfocus.com
    
    

    On Thu, Nov 21, 2002 at 12:15:27PM +1300, Simon Byrnand wrote:
    > At 18:01 16/11/02 +0100, Miguel Angel Rodríguez Jódar wrote:
    >
    > [...]
    > This makes it possible to tell the difference with a scanner between a TCP
    > port which is really closed (sends a RST) and a TCP port that is firewalled
    > with REJECT. (Sends an ICMP DEST UNREACH)

    A scanner checks the UDP ports by sending a packet if there is no answer it
    assumes that the port is open (if the machine is up) it is closed if there
    is a "port-unreachable-ICMP" message (as far as I understood the scanners)

    For TCP a scanner can differentiate between OPEN, CLOSED and FILTERED ports
    by the message that is comming back (or not comming back)...

    have a nice day
    Pierre

    > Regards,
    > Simon
    >



    Relevant Pages

    • RE: SSH connection attempts in logs.
      ... I would suggest the OP look into something like denyhosts or sshdblock. ... SSH connection attempts in logs. ... firewall a specific port. ... It's some kind of port scanner very likely. ...
      (Security-Basics)
    • Re: Changing from MS
      ... Go to Packman and download the latest Sane and Xsane ... and especially LIBIEEE1284 library (if it runs off the parallel port). ... You cannot use the YAST hardware scanner to set it up. ... Linux is progressing at an even faster rate than Windows is, ...
      (alt.os.linux.suse)
    • Re: SSH connection attempts in logs.
      ... Why would you need a secure shell if you didn't care who was connecting to your boxen? ... What I typically do to circumvent the default for scanners and similar ilk is to just change the port that ssh is on or to forward from the firewall a specific port. ... I have also seen mention of 'knock' style programs but have not had the spare time to implement a working 'knock' setup. ... It's some kind of port scanner very likely. ...
      (Security-Basics)
    • Re: Multifunction Printer
      ... Shut off all peripherals like the printer, speakers, ... functioning properly, many times, I also bought a new USB cable so that I ... > USB Local Port Canon MPC 200 Printer. ... Scanner may be turned off, ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Security of Port 3389
      ... port and there is only 64k ports in total. ... run your cable modem to a router, close every port at the router, only open ... scanner running on them. ... checking for security updates once a week also. ...
      (microsoft.public.windowsxp.work_remotely)