From: Alistair Tonner <Alistair@nerdnet.ca>
To: Ranjeet Shetye <ranjeet.shetye2@zultys.com>, Linux <linux@usermail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Fighting back
Date: Fri, 17 Jan 2003 20:41:32 -0500 [thread overview]
Message-ID: <200301172041.32136.Alistair@nerdnet.ca> (raw)
In-Reply-To: <1042817187.516.3.camel@ranjeet-linux-1>
I'm inclined to agree with these folks ... I would rather think
that TARPIT would be more to appropos what you would like ...
further it would at least make that scan a longish one ...
although I suppose that would depend on the scanning software
being used..... as well as the true skill level of the scanner. Keep
in mind that althought there are a lot of script kiddies out there,
there are still some folks with more skill than good graces or
brains, and they will manage to do something with what ever you
give them ... (Gotta love DROP ... )
Alistair
On January 17, 2003 10:26 am, Ranjeet Shetye wrote:
> if a spammer locates 2 people with MIRROR on, and sends spam to A while
> spoofing's B's address as source, you've got disaster on hand.
>
> if you really piss off an intelligent spammer (is there such a thing ?),
> he/she might set you up by spoofing your IP to N other MIRROR sites,
> effectively forcing you to execute a DDoS on yourself.
>
> Be careful what you wish for :D
>
> Ranjeet.
>
> On Sat, 2003-01-18 at 00:27, Linux wrote:
> > That's a very good point.
> >
> > Hmmm... More thinking needed.
> >
> > Linux_303
> >
> >
> > ----- Original Message -----
> > From: "SBlaze" <dagent.geo@yahoo.com>
> > To: "Linux" <linux@usermail.com>
> > Sent: Friday, January 17, 2003 12:22 PM
> > Subject: Re: Fighting back
> >
> > > I think its safe to say we would all like to give a little back to
> > > those
> >
> > who
> >
> > > repeatedly bombard us with useless scans... What you want to do can
> > > "theoretically" be done with the MIRROR jump. Should it be done?
> > > Probably
> >
> > not.
> >
> > > Once an attacker learns they are in a sence scaning themselves.... they
> >
> > can
> >
> > > easily go about some sort of spoofing method in which the SRC IP is a
> >
> > target as
> >
> > > opposed to himself. You could easily find yourself a man in the middle
> > > of
> >
> > a DOS
> >
> > > attack against someone.
> > >
> > > I wouldn't do this... but hey it's up to you
> > >
> > > SBlaze
> > >
> > > --- Linux <linux@usermail.com> wrote:
> > > > Hello all,
> > > >
> > > > I feel that rpc and netbois scans to my network from the outside are
> > > > an obvious attempt to see what I have open, and I'm sure all of you
> > > > would
> >
> > agree.
> >
> > > > Because I run NFS only via my internal network, there are no
> > > > machines
> >
> > that
> >
> > > > would connect via my external interface. I am going to institute a
> > > > rule
> >
> > that
> >
> > > > will cause a person scanning on ports 32770:32789 and 137 to redirect
> >
> > and
> >
> > > > scan the ports on the src IP address. In essence, anyone scanning
> > > > me,
> >
> > will
> >
> > > > be basically scanning themselves.
> > > >
> > > > All I am asking is for some input to this and whether it is a good
> > > > idea
> >
> > or
> >
> > > > not.
> > > >
> > > > Thank you,
> > > >
> > > > Linux_303
> > >
> > > =====
> > > "No touchy NO TOUCHY! Emperor Kuzko -=Emperor's New Groove=-"
> > >
> > > __________________________________________________
> > > Do you Yahoo!?
> > > Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
> > > http://mailplus.yahoo.com
next prev parent reply other threads:[~2003-01-18 1:41 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20030117192237.66443.qmail@web40206.mail.yahoo.com>
2003-01-17 23:27 ` Fighting back Linux
2003-01-17 15:26 ` Ranjeet Shetye
2003-01-18 1:41 ` Alistair Tonner [this message]
2003-01-17 18:57 Linux
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200301172041.32136.Alistair@nerdnet.ca \
--to=alistair@nerdnet.ca \
--cc=linux@usermail.com \
--cc=netfilter@lists.netfilter.org \
--cc=ranjeet.shetye2@zultys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox