From: Ranjeet Shetye <ranjeet.shetye2@zultys.com>
To: Linux <linux@usermail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Fighting back
Date: 17 Jan 2003 16:26:26 +0100 [thread overview]
Message-ID: <1042817187.516.3.camel@ranjeet-linux-1> (raw)
In-Reply-To: <002501c2be7f$fad767a0$6301a8c0@VAIO>
if a spammer locates 2 people with MIRROR on, and sends spam to A while
spoofing's B's address as source, you've got disaster on hand.
if you really piss off an intelligent spammer (is there such a thing ?),
he/she might set you up by spoofing your IP to N other MIRROR sites,
effectively forcing you to execute a DDoS on yourself.
Be careful what you wish for :D
Ranjeet.
On Sat, 2003-01-18 at 00:27, Linux wrote:
> That's a very good point.
>
> Hmmm... More thinking needed.
>
> Linux_303
>
>
> ----- Original Message -----
> From: "SBlaze" <dagent.geo@yahoo.com>
> To: "Linux" <linux@usermail.com>
> Sent: Friday, January 17, 2003 12:22 PM
> Subject: Re: Fighting back
>
>
> > I think its safe to say we would all like to give a little back to those
> who
> > repeatedly bombard us with useless scans... What you want to do can
> > "theoretically" be done with the MIRROR jump. Should it be done? Probably
> not.
> >
> > Once an attacker learns they are in a sence scaning themselves.... they
> can
> > easily go about some sort of spoofing method in which the SRC IP is a
> target as
> > opposed to himself. You could easily find yourself a man in the middle of
> a DOS
> > attack against someone.
> >
> > I wouldn't do this... but hey it's up to you
> >
> > SBlaze
> >
> >
> > --- Linux <linux@usermail.com> wrote:
> > > Hello all,
> > >
> > > I feel that rpc and netbois scans to my network from the outside are an
> > > obvious attempt to see what I have open, and I'm sure all of you would
> agree.
> > > Because I run NFS only via my internal network, there are no machines
> that
> > > would connect via my external interface. I am going to institute a rule
> that
> > > will cause a person scanning on ports 32770:32789 and 137 to redirect
> and
> > > scan the ports on the src IP address. In essence, anyone scanning me,
> will
> > > be basically scanning themselves.
> > >
> > > All I am asking is for some input to this and whether it is a good idea
> or
> > > not.
> > >
> > > Thank you,
> > >
> > > Linux_303
> > >
> >
> >
> > =====
> > "No touchy NO TOUCHY! Emperor Kuzko -=Emperor's New Groove=-"
> >
> > __________________________________________________
> > Do you Yahoo!?
> > Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
> > http://mailplus.yahoo.com
> >
>
>
>
--
Ranjeet Shetye
Senior Software Engineer
Zultys Technologies
Ranjeet dot Shetye2 at Zultys dot com
http://www.zultys.com/
next prev parent reply other threads:[~2003-01-17 15:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20030117192237.66443.qmail@web40206.mail.yahoo.com>
2003-01-17 23:27 ` Fighting back Linux
2003-01-17 15:26 ` Ranjeet Shetye [this message]
2003-01-18 1:41 ` Alistair Tonner
2003-01-17 18:57 Linux
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1042817187.516.3.camel@ranjeet-linux-1 \
--to=ranjeet.shetye2@zultys.com \
--cc=linux@usermail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox