Re: Online Arrmor
- From: Volker Birk <bumens@xxxxxxxxxxx>
- Date: Sun, 15 Mar 2009 07:31:59 +0100 (CET)
Ansgar -59cobalt- Wiechers <usenet-2009@xxxxxxxxxxxxxxxx> wrote:
Volker Birk <bumens@xxxxxxxxxxx> wrote:^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
The output of these tools doesn't say anything at all about which
*sigh* This is regardless of the operating system. Because none of theseports are accessible from the OUTSIDE.If so, throw away your operating system.
tools know anything about packet filters. Neither local, nor remote.
Maybe you want to correct that then.
As you know quite well, the proper way to do that is a port scan.A local packet filter may or may not allow connections to port X.Clear. If you're using a filtering implementation, read the config and
check the status of it additionally.
Not only. As you know, most filtering implementations are dynamic, i.e.
with FTP helpers or even port knocking. You cannot see that with a port
scan.
[...]
The wrong thing with it is, that he may believe that what this toolI'd like to see proof for that claim.
shows is how his box is behaving. The reality often is, that on the
way to the testing server the net is being modified by the
inter-connecting networks.
In many cases, you're scanning not your box but some NAT box outside
or even some proxy server from the outside.
It's so easy, Ansgar: many Internet providers are filtering. People are
using such remote scanning and are thinking, that the words "your
computer has the following ports closed" mean, that their computer has
them closed. It just means, that someone sent a TCP NACK or some ICMP
port unreachable.
Someone.
And with "stealth" it's even worse: that means, someone on the line,
maybe the box itself, did throw away packets.
Your users don't recognize the difference in scanning results. But I saw
the other way arround, too:
I was in a hotel in Spain. When I was scanning from the outside, my Box
had port 25 open. What?
Wenn I was scanning from the inside, every box in the outside had port
25 open.
The reason was, that this hotel did redirect any transport of any IP
address to their filtering mail server. It did not matter which mail
server you were trying to reach, they connected your TCP socket to any
IP address port 25 to their own box.
In this case, NAT did not make a difference, because they had none.
And of course, their mail server was as b0rken as their network setup,
so I used my own to send mail through an SSH tunnel to my server.
Yours,
VB.
--
Bitte beachten Sie auch die Rückseite dieses Schreibens!
.
- Follow-Ups:
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Re: Online Arrmor
- References:
- Online Arrmor
- From: Jim S
- Re: Online Arrmor
- From: DevilsPGD
- Re: Online Arrmor
- From: Geoff Smith
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Re: Online Arrmor
- From: Geoff Smith
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Re: Online Arrmor
- From: Volker Birk
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Re: Online Arrmor
- From: Volker Birk
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Re: Online Arrmor
- From: Volker Birk
- Re: Online Arrmor
- From: Ansgar -59cobalt- Wiechers
- Online Arrmor
- Prev by Date: Re: Online Arrmor
- Next by Date: Re: It seems every firewall is slagged as snake oil. So how should it be done?
- Previous by thread: Re: Online Arrmor
- Next by thread: Re: Online Arrmor
- Index(es):
Relevant Pages
|