Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Matt Hellman" <netfilter@taxandfinance.com>
To: waltdnes@waltdnes.org, 'Netfilter list' <netfilter@lists.netfilter.org>
Subject: RE: T-Pot (TCP HoneyPot) idea
Date: Thu, 10 Apr 2003 21:51:10 -0500	[thread overview]
Message-ID: <000001c2ffd5$35a5a400$fd0aa8c0@winxp> (raw)
In-Reply-To: <20030410220741.GA32442@m1800>

I'm not terribly well versed in the various flag settings during session
setup and tear down, however this doesn't seem likely to be very effective.
The end result would probably just be a lot more traffic on your own little
connection to the Internet.  Or worse, someone could figure out what you're
doing and flood you with SYN packets with spoofed source addresses.  It may
not effect the resources on your firewall (assuming your not keeping the
connection state) but others sure won't appreciate getting a bunch of
SYN-ACK packets from you;) 

>>-----Original Message-----
>>From: netfilter-admin@lists.netfilter.org 
>>[mailto:netfilter-admin@lists.netfilter.org] On Behalf Of 
>>waltdnes@waltdnes.org
>>Sent: Thursday, April 10, 2003 5:08 PM
>>To: Netfilter list
>>Subject: T-Pot (TCP HoneyPot) idea
>>
>>
>>  I'm sure every here has seens lots of SYN-packets in their logs,
>>trying to connect to various ports they shouldn't be talking to.  I
>>don't run any public servers, and I use passive ftp, so I simply block
>>all connection attempts.  The general procedure is to drop the packet,
>>and ignore it.  What would be the effect of sending back a SYN-ACK
>>packet (and anything else necessary?) to fake the setting up of a
>>connection... and then dropping the packet and ignoring it ?
>>
>>  Would an infected machine scanning the net eventually run into
>>resource limits and DOS itself ?  I'm sure that professional crackers
>>can work around this, but if we can make things a bit more painful for
>>skiddies and automatic worms, then let's do it.
>>
>>  Can such trickery be pulled off with a current bog-standard 
>>iptables,
>>or does someone need to write a new "target"?
>>
>>-- 
>>Walter Dnes <waltdnes@waltdnes.org>
>>An infinite number of monkeys pounding away on keyboards will
>>eventually produce a report showing that Windows is more secure,
>>and has a lower TCO, than linux.
>>



  parent reply	other threads:[~2003-04-11  2:51 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-04-10 22:07 T-Pot (TCP HoneyPot) idea waltdnes
2003-04-10 22:20 ` Bob Keyes
2003-04-10 22:36 ` Michael H. Warfield
2003-04-11  2:51 ` Matt Hellman [this message]
2003-04-11  4:46   ` Bob Keyes
2003-04-11 21:17     ` Matt Hellman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='000001c2ffd5$35a5a400$fd0aa8c0@winxp' \
    --to=netfilter@taxandfinance.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=waltdnes@waltdnes.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox