From: Cedric Blancher <blancher@cartel-securite.fr>
To: Jason Dixon <jasondixon@myrealbox.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: State of Stateful Inspection
Date: 25 Oct 2002 10:21:55 +0200 [thread overview]
Message-ID: <1035534115.9045.9.camel@elendil> (raw)
In-Reply-To: <1035489978.1558.27.camel@lappy.fuzzypenguin.net>
Le jeu 24/10/2002 à 22:06, Jason Dixon a écrit :
> I'm about to become a migrated iptables user, but I had a couple of
> questions about the stateful abilities of netfilter. First, it appears
> that true sequence number analysis is available via this "patch-o-matic"
> thingy. At what point does this feature become part of the default
> release?
Well, you should ask netfilter-devel mailing list ;)
But, as the patch is still in patch-o-matic extra section, I do not
think it will be submitted to kernel soon.
> Also, does netfilter support any sort of sequence modulation to
> strengthen the randomness of weak tcp implementations?
No.
But you can use third party patch walled IP Personality :
http://ippersonality.sourceforge.net/
This patch aims at fooling OS fingerprinting systems such as nmap by
modifying network stack behaviours, both locally and for routed packets.
In particular, you can act on ISNs, and so randomize them for network
that are behind your firewall.
Beware : this patch can also weaken your architecture if you decide to
"export" OS fingerprints like Dreamcasts or HP printers ;)
--
Cédric Blancher <blancher@cartel-securite.fr>
Consultant en sécurité des systèmes et réseaux - Cartel Sécurité
Tél: +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99
PGP KeyID:157E98EE FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE
next prev parent reply other threads:[~2002-10-25 8:21 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-24 20:06 State of Stateful Inspection Jason Dixon
2002-10-25 8:21 ` Cedric Blancher [this message]
2002-10-25 10:44 ` Oskar Andreasson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1035534115.9045.9.camel@elendil \
--to=blancher@cartel-securite.fr \
--cc=jasondixon@myrealbox.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.