Re: Scan of TCP 552-554

From: Rodrigo Barbosa (rodrigob_at_suespammers.org)
Date: 07/30/03

  • Next message: Barry Fitzgerald: "Re: Importance of outbound traffic filtering"
    Date: Wed, 30 Jul 2003 17:59:07 -0300
    To: Chris Shepherd <chriss@whstuart.com>
    
    
    

    On Wed, Jul 30, 2003 at 09:58:42AM -0400, Chris Shepherd wrote:
    > You specifically say you have to trust your firewall, and then try and conceal
    > its presence. The point in question is whether or not making it look like a
    > real machine will delay an attacker more than simply dropping all traffic. IMHO
    > the latter is the better overall solution, since once your firewall has been
    > discovered, it will slow and frustrate attempts on your network.

    Lemme do same diet-quoting here.

    You are right, of course. The thing I'm attempting is to make them
    hit my traps faster, so I can react faster. And, as I said, I don't
    think we should use the same method everywhere. Sametime I use
    DROP, sometimes I use tcp-reset and sometimes, icmp-replies.

    As far as I got from this discussion, every method is about as good
    as the other. All have advantages and problems. The real question is
    how to balance them all to have the most benefits of each one of them.
    Care to comment on this one ?

    []s

    -- 
    Rodrigo Barbosa <rodrigob@suespammers.org>
    "Be excellent to each other ..." - Bill & Ted (Wyld Stallyns)
    
    



  • Next message: Barry Fitzgerald: "Re: Importance of outbound traffic filtering"

    Relevant Pages

    • Re: Exploit through firewall question
      ... I perform vulnerability analysis on our outside web presense, usually during development and then after it's been deployed. ... Mgmt wants me to only test through the firewall as if I'm coming in like the public. ... Tools like core impact follow this logic of exploiting an external point of presence then tunneling or burrowing through to the next concentric network access rings potentially performing network scanning of all ports from the compromised point to other internal nodes. ... You have an option to go with a managed service or an enterprise software. ...
      (Pen-Test)
    • Re: MSN
      ... >> Instant Messaging and Presence ... >> communication through a firewall or NAT device. ...
      (microsoft.public.security)
    • Re: Do I need a 2nd Firewall?
      ... A firewall can alert you to their presence by ... detecting their behavior. ...
      (microsoft.public.windowsxp.general)
    • firewall needs
      ... I need a firewall that has the following characteristics: ... No indication of it's presence in Msconfig, Close Program items, Start Menu ... No notification for any incoming or outgoing traffic. ...
      (comp.security.firewalls)