UPD security question

From: Anthony Ewell (aewell_at_gbis.com)
Date: 02/28/04


Date: Fri, 27 Feb 2004 19:05:29 -0800

Hi All,

     Forgive me if this question is too dumb.

     My iptables firewall blocks all incoming SYN
packets ( -p tcp ! --syn ). It also blocks all
incoming UDP packets.

      If have been requested to open one port to UDP
packets (I will use "-s" to only allow the one IP address
through).

    Since there is no such thing as !SYN for UDP
packets, am I opening myself up to any mischief?
Can UDP get an unrequested opening (socket?) from me?

Many thanks,
--Tony
aewell@gbis.com

-- 
-------------------------
I Fish.  Therefore, I am.
-------------------------


Relevant Pages

  • RE: FW: monitor ALL connections to ALL ports
    ... if you want to put the effort into it is to write a program that accepts all packets from ipfw and then logs what you want before returning the untouched packed back to ipfw. ... > more useful to log only opening of the connection; ... If this message contains password-protected attachments, the files have NOT been scanned for viruses by the ING mail domain. ...
    (FreeBSD-Security)
  • Re: Possible security problem?
    ... > My network utility says that this address is in Hungary. ... incoming UDP packets to port 1026. ... Can you find a way to examine those packets? ...
    (comp.security.firewalls)
  • Re: TAMMIE-----
    ... packets of that around? ... As for opening the freezer, keep in mind that it is a heat pump that ... opening it will actually increase inside ...
    (rec.birds)
  • Re: Hook incoming packets
    ... mission easier, or should I use protocol ... Actually all I need is sniffing the incoming UDP packets, ... duplicated packets, then transmit them to their new destination ( ...
    (microsoft.public.win32.programmer.networks)
  • Re: Hook incoming packets
    ... Delving a little in some references I saw that WinpCap/LibPCap can also ... Actually all I need is sniffing the incoming UDP packets, duplicating ...
    (microsoft.public.win32.programmer.networks)