Re: Port Knocking questions

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 03/02/04

  • Next message: Josh Mills: "RE: Protecting Multiple Public IP Workstations"
    Date: Tue, 2 Mar 2004 02:03:35 +0100
    To: security-basics@securityfocus.com
    
    

    On 2004-03-01 H Carvey wrote:
    > > Does it require the hacker to be able to ping the device?
    >
    > Again, it depends on the implementation. If the author of the
    > application using port knocking requires an ICMP packet to be in the
    > mix, then the answer would be "yes".

    Not necessarily. I suppose we can assume that "being able to ping" means
    that the remote host will respond with icmp-echo-replies to icmp-echo-
    requests. For ICMP-based port-knocking (does this make sense at all,
    since ICMP does not have ports?) the host will only need to log incoming
    ICMP packets, but won't have to send echo-replies. Thus the caller won't
    be able to ping the device.

    Regards
    Ansgar Wiechers

    ---------------------------------------------------------------------------
    Free 30-day trial: firewall with virus/spam protection, URL filtering, VPN,
    wireless security

    Protect your network against hackers, viruses, spam and other risks with Astaro
    Security Linux, the comprehensive security solution that combines six
    applications in one software solution for ease of use and lower total cost of
    ownership.

    Download your free trial at
    http://www.securityfocus.com/sponsor/Astaro_security-basics_040301
    ----------------------------------------------------------------------------


  • Next message: Josh Mills: "RE: Protecting Multiple Public IP Workstations"

    Relevant Pages

    • Re: Removing ping/icmp from a network
      ... vendors / admins / whatever. ... A ping sweep isn't the only way to do network exploration. ... which won't gain you any security. ...
      (Security-Basics)
    • Re: WMI/COM and ExecNotificationQueryAsync for Win32_NTLogEvent
      ... because such computer excluded from the network the ping would fail. ... So it seems that I need to set up security ... thing or a WQL query issue, ... listener via ExecNotificationQueryAsync in a C++/COM environment, ...
      (microsoft.public.win32.programmer.networks)
    • Re: Help - Tried almost everything!
      ... or is this the response to your ping ... OTOH, paranoia is ... >I hate spam - PLEASE get rid of the spam before emailing ... ICMP Packet that is the first thing picked up by McAfee ...
      (microsoft.public.security)
    • Re: Scaring malicious visitors...
      ... >I don't think the visitor is really a good hacker or that he's using a ... >Doing a ping in the IP lets him know that I'm aware of his presence and he ... unless someone is actively monitoring log entries for their firewall. ...
      (microsoft.public.inetserver.iis.security)
    • Re: failed shields up test
      ... when you ping a machine that isn't there, you get a reply *from the ... ISP* in form of an ICMP packet that says "the IP you just pinged isn't ... from the IP will return a "Destination Host Unreachable" response. ...
      (alt.os.linux.suse)