(no subject)

From: Tim Haynes (usenet@stirfried.vegetable.org.uk)
Date: 10/31/02


From: Tim Haynes <usenet@stirfried.vegetable.org.uk>
Date: Thu, 31 Oct 2002 00:42:27 +0000


"Clifton T. Sharp Jr." <clifto@clifto.com> writes:

>> >> Can you give pointers to the source where it oversteps the bounds
>> >> described above?
>> >
>> > Well, right after it says it's completely anonymous, it tells you it
>> > records both source and destination address from every datagram.
>>
>> How else would you expect something fulfilling the description of "agent
>> listening for SYN packets" to operate?
>
> I understand and agree. But that takes away any vestige of truth in the
> claim of complete anonymity, doesn't it? (Note that that's the only part
> I'm taking issue with.)

What if the destination IP# does not terminate on the box sending the
reports, ie if you run it on a router, or if someone sends you spoofed
packets?

In that case, it's the source IP# of the report back to them that may or
may not be noted; that's a different kettle of fish to me from the contents
of a packet that is being reported, and you'll have to either take them at
their word, or fling the Data Protection Act (substitute local national
equivalent) at them to be sure they weren't recording a correlation.

~Tim

-- 
Back on the stamping ground                 |piglet@stirfried.vegetable.org.uk
Where it all began                          |http://spodzone.org.uk/



Relevant Pages

  • (no subject)
    ... >>> records both source and destination address from every datagram. ... >> listening for SYN packets" to operate? ... > claim of complete anonymity, ... reports, ie if you run it on a router, or if someone sends you spoofed ...
    (comp.os.linux.security)
  • (no subject)
    ... >>> records both source and destination address from every datagram. ... >> listening for SYN packets" to operate? ... > claim of complete anonymity, ... reports, ie if you run it on a router, or if someone sends you spoofed ...
    (comp.security.firewalls)
  • (no subject)
    ... >>> records both source and destination address from every datagram. ... >> listening for SYN packets" to operate? ... > claim of complete anonymity, ... reports, ie if you run it on a router, or if someone sends you spoofed ...
    (comp.security.misc)
  • Re: Problem with multiple IPs assigned to one server behind PIX 501...
    ... >> I am having a problem with my PIX 501. ... >>SERVERA, but I also need 209.14.222.102 to go to SERVERA, and the only ... > ping packets, the PIX would not have any way of knowing which IP ... > Think of it from the point of view of what the source and destination ...
    (comp.dcom.sys.cisco)
  • RE: Using Snort to find creditcard data?
    ... network transmission took place with between two IP sockets ... some number of bytes and packets were transmitted, ... the destination address is or is not within expectations ...
    (Focus-IDS)