iptables and port scan detection

From:
Date: 10/29/02


Date: Wed, 30 Oct 2002 03:56:31 +1000

Either the various portscans I constantly recieve have suddenly stopped, or
the firewall is blocking them before they reach portsentry. Is there a way
to permit information in, yet still show the system as stealthed? (There
are some open ports, so I want to be able to block an IP temporarially,
before their scan finds any of the open ports)

Furthermore, the firewall makes it difficult to stealth everything, and yet
still be able to run programs which need to open up temporary listening
ports. Can an iptables rule be set to match any new connection to a
non-listening port?

Also, I've seen rules thrown about for all sorts of strange tcp flags and
addresses. What rules for strange behaviour do people use?



Relevant Pages

  • Re: Virtual Private Network - Beware its a Hackers Secret
    ... So checking for open ports no matter ... The reason for this is because a malicious hacker ... If _you_ did a tiny bit of work, you'd install a Firewall to keep people out, ...
    (comp.security.firewalls)
  • Re: Any suggestions?
    ... trying to get the Kerio program to recognize the proxy browser, ... We have scanned your system for open ports and for ports visible to others ... > "Firewall" tab to "Ask Me First". ... > then see the five or six default rules supplied by Kerio. ...
    (comp.security.firewalls)
  • Re: Virtual Private Network - Beware its a Hackers Secret
    ... So checking for open ports no matter ... The reason for this is because a malicious hacker ... If _you_ did a tiny bit of work, you'd install a Firewall to keep people out, ...
    (alt.computer.security)
  • Re: Virtual Private Network - Beware its a Hackers Secret
    ... So checking for open ports no matter ... The reason for this is because a malicious hacker ... If _you_ did a tiny bit of work, you'd install a Firewall to keep people out, ...
    (microsoft.public.security)
  • Re: Is the Gaobot virus blocked with a firewall?
    ... It would depend, I think, upon the type of firewall used and how it is ... Lock down the open ports and nothing is getting in. ... To have an IRC channel, there is an open port through ... >> You're confusing how it infects with how attackers can use an IRC ...
    (microsoft.public.windowsxp.general)