Blocking Port scans
From: BSK (bishan4u_at_yahoo.co.uk)
Date: 10/24/05
- Previous message: Tim: "Re: Confirmation on Loadbalancing"
- Next in thread: Ivan .: "Re: Blocking Port scans"
- Reply: Ivan .: "Re: Blocking Port scans"
- Maybe reply: Josh Perrymon: "RE: Blocking Port scans"
- Reply: robert_at_dyadsecurity.com: "Re: Blocking Port scans"
- Reply: Justin: "Re: Blocking Port scans"
- Reply: Terry Vernon: "Re: Blocking Port scans"
- Reply: Chris Moody: "Re: Blocking Port scans"
- Reply: Georgi Alexandrov: "Re: Blocking Port scans"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 24 Oct 2005 12:34:30 +0100 (BST) To: pen-test@securityfocus.com
Hello Everyone,
Just wanted some feedback from you people. I'm doing a
Firewall Assessment for a CISCO PIX firewall. The
firewall allows SYN, FIN, NULL and XMAS scans but
blocks ACK scans (largely means its a stateful
firewall).
Now what do we do to block the scans that are allowed.
I think it should be easy to block FIN, NULL and XMAS
scans but how do we block or limit or workaround a SYN
scan. 1 way that I think is probably blocking or
limiting the packets from the source (using IDS/IPS)
Looking ahead to some ideas, thoughts, hints.
thns bshan
___________________________________________________________
To help you stay safe and secure online, we've developed the all new Yahoo! Security Centre. http://uk.security.yahoo.com
------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:
Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------
- Previous message: Tim: "Re: Confirmation on Loadbalancing"
- Next in thread: Ivan .: "Re: Blocking Port scans"
- Reply: Ivan .: "Re: Blocking Port scans"
- Maybe reply: Josh Perrymon: "RE: Blocking Port scans"
- Reply: robert_at_dyadsecurity.com: "Re: Blocking Port scans"
- Reply: Justin: "Re: Blocking Port scans"
- Reply: Terry Vernon: "Re: Blocking Port scans"
- Reply: Chris Moody: "Re: Blocking Port scans"
- Reply: Georgi Alexandrov: "Re: Blocking Port scans"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|