Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Should be an easy one.........
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
FINITE
Guru
Guru


Joined: 10 May 2002
Posts: 449

PostPosted: Fri Jul 26, 2002 11:19 am    Post subject: Should be an easy one......... Reply with quote

I can't figure out how to get the monmotha firewall script to "STEALTH" all closed ports so that they do not respond to queries. Being "CLOSED" is fine and all but no response is better. I am pretty sure its this option "DROP="TREJECT"" and should be set to DROP. What the heck is TREJECT? No biggy just wondering. Thanks.
Back to top
View user's profile Send private message
pjp
Administrator
Administrator


Joined: 16 Apr 2002
Posts: 20588

PostPosted: Fri Jul 26, 2002 5:42 pm    Post subject: Reply with quote

The Oracle says this:
Quote:
DROP="TREJECT" # What to do with packets we don't want: DROP, REJECT, TREJECT (Reject with
tcp-reset for TCP), LDROP (log and drop), LREJECT (log and reject),
LTREJECT (log and reject with tcp-reset)

_________________
Quis separabit? Quo animo?
Back to top
View user's profile Send private message
FINITE
Guru
Guru


Joined: 10 May 2002
Posts: 449

PostPosted: Sat Jul 27, 2002 10:28 pm    Post subject: Reply with quote

So if i set that to drop then port X would not respond to anything and appear to be no existant?
Back to top
View user's profile Send private message
pjp
Administrator
Administrator


Joined: 16 Apr 2002
Posts: 20588

PostPosted: Sat Jul 27, 2002 10:35 pm    Post subject: Reply with quote

I didn't say I understood it, I just found it :D

Hadn't heard of the program until I read your post. Maybe someone else can elaborate. Have you checked out their mailing list?
_________________
Quis separabit? Quo animo?
Back to top
View user's profile Send private message
FINITE
Guru
Guru


Joined: 10 May 2002
Posts: 449

PostPosted: Sun Aug 04, 2002 12:32 am    Post subject: Reply with quote

Anybody have any ideas?
Back to top
View user's profile Send private message
rfru
n00b
n00b


Joined: 30 Jun 2002
Posts: 11

PostPosted: Sun Aug 04, 2002 4:26 am    Post subject: Reply with quote

whenever the monmotha script matches a packet we don't want it uses the DROP variable to specify the target ( -j ${DROP} ). so, setting the DROP variable to DROP will send no response and simply drop the packet, or effectively being stealth
Back to top
View user's profile Send private message
FINITE
Guru
Guru


Joined: 10 May 2002
Posts: 449

PostPosted: Sun Aug 04, 2002 4:44 am    Post subject: Reply with quote

Cool, thats what i thought. Thanks man :)
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum