Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Alistair Tonner <Alistair@nerdnet.ca>
To: Ranjeet Shetye <ranjeet.shetye2@zultys.com>, Linux <linux@usermail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Fighting back
Date: Fri, 17 Jan 2003 20:41:32 -0500	[thread overview]
Message-ID: <200301172041.32136.Alistair@nerdnet.ca> (raw)
In-Reply-To: <1042817187.516.3.camel@ranjeet-linux-1>


	I'm inclined to agree with these folks ... I would rather think
	that TARPIT would be more to appropos what you would like ... 
	further it would at least make that scan a longish one ... 
	although I suppose that would depend on the scanning software 
	being used..... as well as the true skill level of the scanner.  Keep
	in mind that althought there are a lot of script kiddies out there, 
	there are still some folks with more skill than good graces or 
	brains, and they will manage to do something with what ever you
	give them ... (Gotta love DROP ... ) 

	Alistair


On January 17, 2003 10:26 am, Ranjeet Shetye wrote:
> if a spammer locates 2 people with MIRROR on, and sends spam to A while
> spoofing's B's address as source, you've got disaster on hand.
>
> if you really piss off an intelligent spammer (is there such a thing ?),
> he/she might set you up by spoofing your IP to N other MIRROR sites,
> effectively forcing you to execute a DDoS on yourself.
>
> Be careful what you wish for :D
>
> Ranjeet.
>
> On Sat, 2003-01-18 at 00:27, Linux wrote:
> > That's a very good point.
> >
> > Hmmm... More thinking needed.
> >
> > Linux_303
> >
> >
> > ----- Original Message -----
> > From: "SBlaze" <dagent.geo@yahoo.com>
> > To: "Linux" <linux@usermail.com>
> > Sent: Friday, January 17, 2003 12:22 PM
> > Subject: Re: Fighting back
> >
> > > I think its safe to say we would all like to give a little back to
> > > those
> >
> > who
> >
> > > repeatedly bombard us with useless scans... What you want to do can
> > > "theoretically" be done with the MIRROR jump. Should it be done?
> > > Probably
> >
> > not.
> >
> > > Once an attacker learns they are in a sence scaning themselves.... they
> >
> > can
> >
> > > easily go about some sort of spoofing method in which the SRC IP is a
> >
> > target as
> >
> > > opposed to himself. You could easily find yourself a man in the middle
> > > of
> >
> > a DOS
> >
> > > attack against someone.
> > >
> > > I wouldn't do this... but hey it's up to you
> > >
> > > SBlaze
> > >
> > > --- Linux <linux@usermail.com> wrote:
> > > > Hello all,
> > > >
> > > > I feel that rpc and netbois scans to my network from the outside are
> > > > an obvious attempt to see what I have open, and I'm sure all of you
> > > > would
> >
> > agree.
> >
> > > >  Because I run NFS only via my internal network, there are no
> > > > machines
> >
> > that
> >
> > > > would connect via my external interface.  I am going to institute a
> > > > rule
> >
> > that
> >
> > > > will cause a person scanning on ports 32770:32789 and 137 to redirect
> >
> > and
> >
> > > > scan the ports on the src IP address.  In essence, anyone scanning
> > > > me,
> >
> > will
> >
> > > > be basically scanning themselves.
> > > >
> > > > All I am asking is for some input to this and whether it is a good
> > > > idea
> >
> > or
> >
> > > > not.
> > > >
> > > > Thank you,
> > > >
> > > > Linux_303
> > >
> > > =====
> > > "No touchy NO TOUCHY! Emperor Kuzko -=Emperor's New Groove=-"
> > >
> > > __________________________________________________
> > > Do you Yahoo!?
> > > Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
> > > http://mailplus.yahoo.com


  reply	other threads:[~2003-01-18  1:41 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20030117192237.66443.qmail@web40206.mail.yahoo.com>
2003-01-17 23:27 ` Fighting back Linux
2003-01-17 15:26   ` Ranjeet Shetye
2003-01-18  1:41     ` Alistair Tonner [this message]
2003-01-17 18:57 Linux

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200301172041.32136.Alistair@nerdnet.ca \
    --to=alistair@nerdnet.ca \
    --cc=linux@usermail.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=ranjeet.shetye2@zultys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox