Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 29, 2008, 08:48:22 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
187195
Posts
21658
Topics
52479
Members
Latest Member:
wellofsouls
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
General Security Questions and Comments (not product related)
Stealthing ports does not provide "invisibility" protection from hackers
« previous
next »
Pages:
[
1
]
Author
Topic: Stealthing ports does not provide "invisibility" protection from hackers (Read 966 times)
aweir14150
Comodo Family Member
Offline
Posts: 53
Stealthing ports does not provide "invisibility" protection from hackers
«
on:
December 03, 2006, 04:48:24 PM »
because a hacker would still know the computer was there because no Destination Unreachable message would be sent if the computer was connected to the internet.
I was hoping someone could elaborate on this and tell if it's true.
If someone port scanned a computer that did not exist, or if the IP address was not being allocated, the nearest router would send an ICMP 3 (destination unreachable). But if the address
is
being used, the packet makes it to the destination, but the firewall drops it and no Destination Unreachable is sent back. Therefore the hacker knows the IP address exists.
But the problem is that not all routers send destination unreachable ICMP resonses back, but it is a good idea to send the ICMP 3 because it prevents a computer from repeatedly attempting to connect to a non-existing computer.
So in essence if the closest router is supposed to send an ICMP 3 response, but none is returned, then stealthing ports would have no benefit to HIDING your presense because a hacker would know you existed.
I could be completely wrong but this was the general idea that was posed by an "expert" on another forum...these are not my stements. He called most personal firewalls "firewall placebos" and "violating tools".
«
Last Edit: December 03, 2006, 05:13:28 PM by aweir14150
»
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #1 on:
December 03, 2006, 06:20:15 PM »
It has some true in it but is not completely correct.
1.the ICMP 3 response in this chase should be send from the ISP of the IP adress and not by the closest router.
2. There exist routers that have stealthing capabilities (mine has for example)
3. A hacker:
A) or should know your IP and that your pc exists there for attacking you and in this chase is true. Stealthing would not help at all.
B) or is trying to find existing IPs with a spybot ping utility. These applications scan multiple IPs at the same time. Do you think that he will try first to attack the stealthed IPs or the unstealthed IPs? I would certainly go first for the unstealthed.
«
Last Edit: December 03, 2006, 06:29:44 PM by pandlouk
»
Logged
aweir14150
Comodo Family Member
Offline
Posts: 53
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #2 on:
December 03, 2006, 10:11:53 PM »
But it's a paradox because if the ports appear closed, the hacker obviously knows you're there...and if they're steath, the hacker still knows you're there because he did not recieve an ICMP 3 response.
«
Last Edit: December 03, 2006, 10:20:01 PM by aweir14150
»
Logged
aweir14150
Comodo Family Member
Offline
Posts: 53
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #3 on:
December 03, 2006, 10:37:28 PM »
Rather than create a whole new thread I was wondering if it was possible to make a router or software firewall send an ICMP 3 message instead of just dropping the packet, Would this be benificial because instead of just dropping the packet, the firewall would send out a destination unreachable to fool the hacker into thinking the IP adress isn't in use?
I'm just brainstorming right now.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5342
... and I say to myself, "What a wonderful world"
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #4 on:
December 03, 2006, 11:11:51 PM »
Good idea, but how would you cater for someone running a server that needs to be contactable from the outside? In your scenario, no-one would ever be able to initiate an inbound connection.
Just playing Devils advocate. This is an interesting idea you've come up with - anti stealth. Please keep going with this train of thought.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
aweir14150
Comodo Family Member
Offline
Posts: 53
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #5 on:
December 04, 2006, 12:01:19 AM »
Well of course it wouldn't work if you were running a web/mail server, that's why it should be an option within the firewall. I would call it "Cloak" (Send ICMP 3 Destination Unreachable)"
Possible problems:
some people say that stealthing ports creates more traffic on the web because of the repeated attempts to connect to unresponsive ports, but perhaps all those extra ICMP Destination Unreachables would create even MORE traffic.
Also if a hacker already knows that you exist, the ICMP unreachables won't deter him becauser they would be comming from your computer, not your ISP.
And for the sake of network troubleshooting, the biggest problem, how would someone's ISP know if the ICMP unreachable was the result of a savvy firewall or a
real
connection problem? This could wreak havoc with the ISP because they would assume your IP address wasn't in use and try to give it to someone else
I'm sure someone else has way more brains than me and could always come up with a better way. Which is why perhaps the firewall could determine if the port scan was coming from the IANA or your ISP's DNS servers and then just stealth it.
«
Last Edit: December 04, 2006, 12:09:19 AM by aweir14150
»
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5342
... and I say to myself, "What a wonderful world"
Re: Stealthing ports does not provide "invisibility" protection from hackers
«
Reply #6 on:
December 04, 2006, 12:09:29 AM »
Quote from: aweir14150 on December 04, 2006, 12:01:19 AM
Well of course it wouldn't work if you were running a web/mail server, that's why it should be an option within the firewall. I would call it "Cloak" (Send ICMP 3 Destination Unreachable)"
Possible problems:
some people say that stealthing ports creates more traffic on the web because of the repeated attempts to connect to unresponsive ports, but perhaps all those extra ICMP Destination Unreachables would create even MORE traffic.
Also if a hacker already knows that you exist, the ICMP unreachables won't deter him becauser they would be comming from your destination computer, not the ISP.
And for the sake of network troubleshooting, the biggest problem, how would someone's ISP know if the ICMP unreachable was the result of a savvy firewall or a
real
connection problem? This could wreak havoc with the ISP because they would assume your IP address wasn't in use and try to give it to someone else
I'm sure someone else has way more brains than me and could always come up with a better way.
The main problem with the concept of a firewall that sends ICMP 3 msgs back is precisely the one you have piointed out - DHCP leases not being renewed and your current IP being relet to someone else on the same subnet.
Also, P2P would fail, as would online gaming if someone was starting an online game on their local PC - BattleNet, COD etc.
Interesting thought though.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.42 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com