View previous topic :: View next topic |
Author |
Message |
FINITE Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/440d91063d918393b9b7a.jpg)
Joined: 10 May 2002 Posts: 449
|
Posted: Fri Jul 26, 2002 11:19 am Post subject: Should be an easy one......... |
|
|
I can't figure out how to get the monmotha firewall script to "STEALTH" all closed ports so that they do not respond to queries. Being "CLOSED" is fine and all but no response is better. I am pretty sure its this option "DROP="TREJECT"" and should be set to DROP. What the heck is TREJECT? No biggy just wondering. Thanks. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pjp Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/1154772887439692d88303b.jpg)
Joined: 16 Apr 2002 Posts: 20588
|
Posted: Fri Jul 26, 2002 5:42 pm Post subject: |
|
|
The Oracle says this:
Quote: | DROP="TREJECT" # What to do with packets we don't want: DROP, REJECT, TREJECT (Reject with
tcp-reset for TCP), LDROP (log and drop), LREJECT (log and reject),
LTREJECT (log and reject with tcp-reset) |
_________________ Quis separabit? Quo animo? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
FINITE Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/440d91063d918393b9b7a.jpg)
Joined: 10 May 2002 Posts: 449
|
Posted: Sat Jul 27, 2002 10:28 pm Post subject: |
|
|
So if i set that to drop then port X would not respond to anything and appear to be no existant? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pjp Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/1154772887439692d88303b.jpg)
Joined: 16 Apr 2002 Posts: 20588
|
Posted: Sat Jul 27, 2002 10:35 pm Post subject: |
|
|
I didn't say I understood it, I just found it
Hadn't heard of the program until I read your post. Maybe someone else can elaborate. Have you checked out their mailing list? _________________ Quis separabit? Quo animo? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
FINITE Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/440d91063d918393b9b7a.jpg)
Joined: 10 May 2002 Posts: 449
|
Posted: Sun Aug 04, 2002 12:32 am Post subject: |
|
|
Anybody have any ideas? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
rfru n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 30 Jun 2002 Posts: 11
|
Posted: Sun Aug 04, 2002 4:26 am Post subject: |
|
|
whenever the monmotha script matches a packet we don't want it uses the DROP variable to specify the target ( -j ${DROP} ). so, setting the DROP variable to DROP will send no response and simply drop the packet, or effectively being stealth |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
FINITE Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/440d91063d918393b9b7a.jpg)
Joined: 10 May 2002 Posts: 449
|
Posted: Sun Aug 04, 2002 4:44 am Post subject: |
|
|
Cool, thats what i thought. Thanks man ![Smile :)](images/smiles/icon_smile.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|