republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Wireless Security » Port 0 and 1 Shows Closed not stealth Please helo
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Question on Mac Filtering »
« How to configure separate, public Inet access on home NW  
AuthorAll Replies


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA

1 edit
reply to chascent
Re: Port 0 and 1 Shows Closed not stealth Please helo

quote:
As stated by SYNACK, closed is as secure as "stealth".
I think a CLOSED port can be detected by a port probe AS A CLOSED PORT... A "Stealthed" port is not detected AT ALL.. (Which is safer)


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
·Comcast Formerly ..

Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL
said by Dude111 See Profile :

...(Which is safer)
That's an old myth.


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

said by SYNACK See Profile :

said by Dude111 See Profile :

...(Which is safer)
That's an old myth.
It is? How so?


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
·Comcast Formerly ..

Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

1 edit
Stealth has exactly one advantage:

It allows relatively clueless users to easily verify with online tools that the firewall software is actually enabled and running.

Here's an old discussion that might shed some light on your questions.

A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline. What do you think is a more graceful handling of a stray packet arriving on the WAN side: (1) Having the router return a RST for a "closed" response, then going back to regular work? (2) triggering a flurry of local LAN and router activity, but resulting in a stealth response to the outside viewer? Though so!


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

said by SYNACK See Profile :

Stealth has exactly one advantage:

It allows relatively clueless users to easily verify with online tools that the firewall software is actually enabled and running.

Here's an old discussion that might shed some light on your questions.

A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline. What do you think is a more graceful handling of a stray packet arriving on the WAN side: (1) Having the router return a RST for a "closed" response, then going back to regular work? (2) triggering a flurry of local LAN and router activity, but resulting in a stealth response to the outside viewer? Though so!
Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.
--
Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
·Comcast Formerly ..

Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL
said by antdude See Profile :

Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.
As long as you forward to a real server you're fine.

jbibe
Premium,MVM
join:2001-02-22


4 edits
reply to SYNACK
said by SYNACK See Profile :

A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline.
Whether or not a person should use the technique depends on how important "stealth" is to the individual, and the probability of a particular port being scanned or flooded during normal operation. In the case of port 0 and port 1, I cannot remember if I have every seen a log entry showing a scan of these ports. It seems to me that the probability of the ports being scanned is essentially zero. Therefore, the probability of exceeding the limit of the NAT is very, very small.

Personally, I don't believe that having port 0 and port 1 show closed during a scan test is important -- the device is secure.


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

reply to SYNACK
said by SYNACK See Profile :

said by antdude See Profile :

Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.
As long as you forward to a real server you're fine.
Yeah, I do. I also use DenyHosts to block brute force attacks.
--
Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer

chascent

join:2005-01-17
182501
Can you run this thru the router??


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

said by chascent See Profile :

Can you run this thru the router??
Run what? DenyHosts? No. Linux/UNIX thing.
-
Forums » Up and Running » Security » Wireless SecurityQuestion on Mac Filtering »
« How to configure separate, public Inet access on home NW  


Sunday, 21-Mar 10:13:52 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10.5 years online! © 1999-2010 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [167] Comcast Confirms 100 Mbps Is Coming
· [126] What You Need To Know About The National Broadband Plan
· [103] The 'Electromagnetically Hypersensitive' Attack Smart Meters
· [77] The FCC Wants Your Thoughts On Comcast/NBC Merger
· [70] 'Lawn Fridges' Attack UK Lawns
· [59] Weekend Open Thread
· [54] FCC Releases Copy Of The National Broadband Plan
· [46] FCC Gives Final Sales Pitch For Broadband Plan
· [42] Satellite: The 'Rodney Dangerfield' Of Broadband Connectivity
· [41] Putting T-Mobile HSPA+ Through Its Paces
Most people now reading
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· LCDguys File Server Pr0n :) - AKA The Horde :) [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· Disney owned HD channels coming 3/25 [OptimumOnline]
· New Commodore 64 [Computer Hardware Discussion/Reviews]
· grounding gurus? comments please (pics attached) [Wireless Service Providers]
· [Speed] Huge Comcast problems, 10+ Tech Calls, no solution. [Comcast HSI]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Pyramid UFO being spoted all over the world!! [56k Lookout (Broadband Heavy)]
· [Rant] HELP! A fradulent charge-off on my credit report. [Rants, Raves, and Praise]