Re: iptables and port scan

From: Cedric Blancher (blancher@cartel-securite.fr)
Date: 02/12/02


From: Cedric Blancher <blancher@cartel-securite.fr>
Date: Tue, 12 Feb 2002 09:08:10 +0000 (UTC)

Dans sa prose, Lutz Donnerhacke (lutz@iks-jena.de) nous ecrivait :
> Dropping legal connections is BAD. Use REJECT instead.
> http://www.blood-thirsty-barbarians.de/Firewall.html#Deny

On an RFC basic, it is true. But, on a behaviour basic, I do not see the
point in using REJECT.
I plug onto Internet a host that provides some services. This services
are "advertised", understand I declare them accessible publicly. Someone
who wants to reach that host has no reason to try connecting to some
other service. If he does so, its behaviour is no more normal, so I do
not see why I should offer him a normal response, even if his connection
is legal on a RFC basic.

-- 
BOFH excuse #414:

tachyon emissions overloading the system



Relevant Pages

  • Re: Strange netstat output - possible hacking attempt?
    ... >> think we can really call that 'port scanning' in any illegitimate sense. ... > out to the colo swerver, the ISP would cut the link, outgoing packets would ... "Requests per 10 seconds per host rule" and only inforcing these rules ... connections making it a WAN. ...
    (comp.os.linux.security)
  • Pocket PC (iPaq 4350) fails to make wireless connection even after replacing motherboard!
    ... Established connections reset: 2 ... Host Name: localhost ... INC Vendor: High Tech Computer ... Host Name: WINDOWSMOBILE97 ...
    (microsoft.public.pocketpc)
  • Re: Error messages for remote desktop connection attempt
    ... Did you enable Remote Desktop connections on the XP Pro host? ... have you checked the EventLog on the host? ... "The net logon service on the local computer started and then ...
    (microsoft.public.windows.terminal_services)
  • Re: Network of 2 desktops, 1 laptop, all WinXP
    ... > Does your host use Zone Alarm?? ... >> proper connections. ... >>> Network CD copied and loaded to a laptop connected by wireless router ... >>> does not show on the second desktop as being part of the network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Too many connections problem
    ... 'Too many connections'. ... section in SendmailConfigFiles: ... single thread deliveries to other ... sendmails on this host to connect ...
    (comp.mail.sendmail)