Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Ranjeet Shetye <ranjeet.shetye2@zultys.com>
To: Linux <linux@usermail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Fighting back
Date: 17 Jan 2003 16:26:26 +0100	[thread overview]
Message-ID: <1042817187.516.3.camel@ranjeet-linux-1> (raw)
In-Reply-To: <002501c2be7f$fad767a0$6301a8c0@VAIO>


if a spammer locates 2 people with MIRROR on, and sends spam to A while
spoofing's B's address as source, you've got disaster on hand.

if you really piss off an intelligent spammer (is there such a thing ?),
he/she might set you up by spoofing your IP to N other MIRROR sites,
effectively forcing you to execute a DDoS on yourself.

Be careful what you wish for :D

Ranjeet.

On Sat, 2003-01-18 at 00:27, Linux wrote:
> That's a very good point.
> 
> Hmmm... More thinking needed.
> 
> Linux_303
> 
> 
> ----- Original Message -----
> From: "SBlaze" <dagent.geo@yahoo.com>
> To: "Linux" <linux@usermail.com>
> Sent: Friday, January 17, 2003 12:22 PM
> Subject: Re: Fighting back
> 
> 
> > I think its safe to say we would all like to give a little back to those
> who
> > repeatedly bombard us with useless scans... What you want to do can
> > "theoretically" be done with the MIRROR jump. Should it be done? Probably
> not.
> >
> > Once an attacker learns they are in a sence scaning themselves.... they
> can
> > easily go about some sort of spoofing method in which the SRC IP is a
> target as
> > opposed to himself. You could easily find yourself a man in the middle of
> a DOS
> > attack against someone.
> >
> > I wouldn't do this... but hey it's up to you
> >
> > SBlaze
> >
> >
> > --- Linux <linux@usermail.com> wrote:
> > > Hello all,
> > >
> > > I feel that rpc and netbois scans to my network from the outside are an
> > > obvious attempt to see what I have open, and I'm sure all of you would
> agree.
> > >  Because I run NFS only via my internal network, there are no machines
> that
> > > would connect via my external interface.  I am going to institute a rule
> that
> > > will cause a person scanning on ports 32770:32789 and 137 to redirect
> and
> > > scan the ports on the src IP address.  In essence, anyone scanning me,
> will
> > > be basically scanning themselves.
> > >
> > > All I am asking is for some input to this and whether it is a good idea
> or
> > > not.
> > >
> > > Thank you,
> > >
> > > Linux_303
> > >
> >
> >
> > =====
> > "No touchy NO TOUCHY! Emperor Kuzko -=Emperor's New Groove=-"
> >
> > __________________________________________________
> > Do you Yahoo!?
> > Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
> > http://mailplus.yahoo.com
> >
> 
> 
> 
-- 
Ranjeet Shetye
Senior Software Engineer
Zultys Technologies
Ranjeet dot Shetye2 at Zultys dot com
http://www.zultys.com/



  reply	other threads:[~2003-01-17 15:26 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20030117192237.66443.qmail@web40206.mail.yahoo.com>
2003-01-17 23:27 ` Fighting back Linux
2003-01-17 15:26   ` Ranjeet Shetye [this message]
2003-01-18  1:41     ` Alistair Tonner
2003-01-17 18:57 Linux

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1042817187.516.3.camel@ranjeet-linux-1 \
    --to=ranjeet.shetye2@zultys.com \
    --cc=linux@usermail.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox