Re: Am I being hacked?

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 08/26/04


Date: Thu, 26 Aug 2004 16:13:01 -0400

On Thu, 26 Aug 2004 18:42:01 +0200, Brian spoketh

>Thanks for clarifying. I did feel that I was being paranoid. However, it
>seems really strange that you have ports that test as 'stealthed' yet
>incoming TCP packets are 'Allowed' on those ports.
>
>Brian
>

Stealth simply means that the firewall will drop a request rather then
respond with the appropriate reply.

The issue of "allowed" packets or not is a little confusing, especially
with a software firewall installed on the computer. It's unclear to me
if the firewall itself actually did the responding or not, or if the
firewall allowed the traffic to get passed, thus leaving it to the OS
and the TCP/IP stack to send the appropriate ICMP response.

Either way, it seems no actual connection was made, so no harm no foul.

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)



Relevant Pages

  • Re: NIS 2002 upgraded to 2003, Stealth ports??
    ... >from Symantec or GRC they both say the ports are closed and not stealth ... >and I should check my firewall settings! ... >I even tried to install NIS 2003 on a clean install of Winxp and it does ...
    (comp.security.firewalls)
  • Re: Someone is Scanning my computer
    ... You don't really need to worry about the actual scan. ... there's no need to worry as you run a firewall. ... if I have this STEALTH classification.. ... Ports Closed ...
    (microsoft.public.windowsxp.basics)
  • Re: OT: Best Antivirus?
    ... especially on a port with some known vulnerability. ... to the target host and wasn't intercepted and dropped by the firewall. ... find open ports. ... a "stealth" firewall, still provides little hope of finding any open ports ...
    (rec.autos.sport.f1)
  • Re: OT: Best Antivirus?
    ... to the target host and wasn't intercepted and dropped by the firewall. ... find open ports. ... a "stealth" firewall, still provides little hope of finding any open ports ... But if there was no telnet service running in the first place where would the vulnerability come from? ...
    (rec.autos.sport.f1)
  • Re: Am I being hacked?
    ... > incoming TCP packets are 'Allowed' on those ports. ... The term "stealth" is misleading. ... The online services that claim to test your firewall can be misleading ... but block normal ICMP echo requests. ...
    (comp.security.firewalls)

Quantcast