When I test my sygate firewall on Gibson's Shields Up. The ports are coming up as closed, but not all are coming up as what GRC calls stealth.
I figure this is to be expected. I have a 'home router'. So my router is blocking incoming connections - including Gibson's, reporting back "Closed". Those ports that my router is allowing through , Sygate kicks in and blocks the incoming connection properly, reporting nothing back - what GRC calls Stealth. Not even giving away my computer's existance.
Is running my home router's firewall along with Sygate, actually makign me less secure than if I was to run Sygate alone ? (since my ports aren't 'stealthed') ?
Didn't find your answer? Ask the community — no account required.
J
jameshanley39
Great links It's right. Gibson is promoting himself by obfuscating technical concepts. IN my book, that is one of the worst crimes. What an asshole. Gibson just lost a fan
thanks for the info
C
charlie R
ports are
"Weltjugendtag"
asshole.
When you connect to a website, it has to read your address, or else you couldn't view it. Gibson also tells you your machine address when you connect to his site. The scanner is a different machine and cannot see your address because you are not connected to it, and your ports are closed or stealth. The server you are connected to can read your IP, and anything else your security settings allow, if it wants to. That's why it's important to block Active X, mobile code, scripts, java, etc, and keep your Internet Security settings high. The firewall helps you keep your computer safe from the "bad stuff". I said "helps". VB will tell you he can get into any machine he wants to, despite personal firewalls. Let's just hope people who do that have bigger fish to fry than us.
charlie R
C
Casey Klc
Run a security check on your Sygate. On the firewall main page, select the Security Button. This takes you to Sygate website. You will find that if your ports are "blocked" (closed), you are in good shape. Casey
J
Jason
Volker Birk :
And you were doing so good until you said use the windows-firewall too.
Jason
J
Jim Scott
You get them all 'blocked' from ZA and XP too!
O
optikl
No. Closed is the "expected" response when a computer outside your subnet tries to connect with your system. Stealth is the equivalent of my asking you a closed-ended question and you choosing to ignore me.
V
Volker Birk
Shields Up is nonsense.
formatting link
You're fooled by the nonsense Gibson is writing and your "Personal Firewall" is telling you.
It is just not possible to make a PC "invisible" or "stealth" in the Internet if it's connected.
Here is your IP address, measured by my server:
formatting link
You don't need Sygate at all. Just use the Windows-Firewall.
Yours, VB.
J
jameshanley39
somebody more-or-less pointed out that what Gibson calls 'stealth' (blocking without giving a response) is no more secure than closed.
their argument for it being no more secure was that they can already find out my ip anyway.
It may be that 'stealth' is slightly - but barely - more secure than closed? Indeed, it probably is, since software firewalls all do it. But what would be your reason for saying that 'stealth' is more secure?
J
jameshanley39
my understanding is-
seems to me that stealth is more secure.
If you ping an ip address that has port 7 - the ICMP port stealthed. Then it will not respond. It will be indistinguishable from a computer that does not exist. somebody port scanning a range of IPs will not know whether your comp exists or has the port stealthed.
However. When you make an outgoing connection, your IP is available to the server receiving it. Regardless of whether any of your ports are stealthed or not.
formatting link
for example. Presumably it just uses the HTTP request you sent it, looks at the IP in the packet, and tells you your IP.
As soon as you make an outgoing connection to anywhere, you give your IP. Or your 'home router' public NATTED ip.
So stealth is more secure but only regarding incoming connections.
I am far from an expert, this is all new to me.
Given info posted in the thread. My gripe with Gibson is him calling his probing 'nanoprobing' as if it's a new technology he invented. it is obfuscating technical material , it seems to me - it is for the purposes of his own self promotion. By doing that, I think his self promotion has crossed the line.
J
jameshanley39
You are responding as if I am a mug that thinks that stealthed ports are infinitely superior. And offer complete protection.
Of course, a careless user would give away all sorts of information, especially on usenet.
Whatever method (be it usenet or anything else) they used to get the hostname containing an ip address. It might not have been via a port scan if ports were stealthed. It's possible a comp is there. Or not.
I know that stealthing ports is NOT absolutely secure by any means. Infact, it offers hardly any more protection. (if any). And if you do other things carelessly, you will get your router's IP told to the world. There are many ways an IP can be visible - if one is careless. I used any outgoing connection as an example. Usenet is another. (assuming no proxy or ip spoofing or anything).
you're saying that unix users don't stealth their ports?
*Another* method (besides usenet) of hackers getting *anybodys* IP, is just doing a port scan. And if a port is stealthed. It doesn't tell him anything. He is left with 2 possibilities. Comp doesn't exist. Or port is stealthed(which according to you, means a 'personal firewall'.
You're saying that unix firewalls tend not to stealth ports. I don't see why unix firewalls tend not to stealth ports. Many hackers do just scan a range of IPs. So stealthing does have that small advantage over closed. Why don't unix users use it? I'm sure they had some other way (spoofing IP? proxy?) for being more anonymous on usenet. But isn't it good to be safer from port scans too?
Anyhow - not that it matters. NAT Devices tend not to stealth ports(the ones I've seen certainly don't). They just report back closed. So if a softare firewall is running and stealthing ports. The ports will be reported back as closed since the 'home router' is hit first.
Perhaps stealthed ports indicate a windows user not behind a router. (not that a windows user behind a router is necessarily any cleverer). Anyhow. I don't see why unix firewalls shouldn't stealth ports. For the above mentinoned reasons.
G
Gary
I'd better register a domain for my new company, Event Horizon Networking. I will build fully buzzword compliant security appliances, spread FUD across the galaxy, and laugh all the way to the bank. When Symantec or Microsoft buys me out and end of lifes all my vaporware products, I'll retire to the Bahamas. Or Betelgeuse.
-Gary
G
Gary
Every once in a while, some idiot yells that security through obscurity is a bad idea. I'd say maybe if that's all you're relying on. But if you think about it, why do soldiers wear camoflauge? Why do chameleons have color changing abilities? Why do some insects have colors that match their background? Because it simply works. Whether you're stealthing or blocking doesn't really matter so long as you're making an active effort to be security conscious. Steve Gibson, Steve Ballmer, and any other frothing at the mouth idiot can yell as loud as they want about security but the signal to noise ratio will still be abysmally low. Just like Usenet.
-Gary
A
Anonymous
It's not just
formatting link
but serveral sites that report security in terms of open, closed, and stealth. For example, take a look at
formatting link
and the Sygate site. And for what its worth, this issue of closed vs stealth has been endlessly debated for more than 3-4 years.
Bottom line ... hell if I know?
L
Leythos
Ping an IP that doesn't have a computer attached and see what you get back.
Ping an IP that is stealthed and see what you get back.
If you see any difference then you know something is there.
K
Keith
So , if I had a static IP and told you what it is, can you tell whether i'm online or not? If I'm stealthed then I'm guessing the answer is no? Otherwise Yes
L
Leythos
Yes, one lets people know you exist, one doesn't.
There is no such thing as a flawless OS, never been created. Start with the idea that everything has holes and you will have it much easier when it comes to security.
M
Moe Trin
It tends to be less secure, as the people who use stealth don't know enough about networking, and nearly always make other ghastly mistakes.
Why do they have to find "your" IP? Why not anyone's IP? Or do you feel that the bad guys are specifically looking for you only. If you are smart enough to NOT install viruses, spyware, trojans or other mal-ware (but it looked so k3w1), then the "attacks" from outside are actually being directed at addresses picked at random. Sorry to disappoint you.
IF DONE RIGHT (and it rarely is), "stealth" offers one and only one advantage. Those who try to connect to your computer won't be able to identify what _operating_system_ you are running. They might _guess_ that you are running XP or something, but they won't be able to positively state that, nor guess on which service packs you've installed, if any. But then why bother - just try using this exploit or that - if it works then we're home free, and if not, move on to the next address.
No, that's marketing pressure - "product A offers to do FOO" - so products B through Z have to do so as well, or be thought to be lacking by the clueless sheep who buy something because it promises to taste better or has less fat, or makes your ***** grow bigger.
I don't say that - but then I've only been using TCP/IP since 1986.
Old guy
J
Jason Edwards
The reason why personal software firewalls all do it is because they know that most of their customers think it's better. Any personal firewall vendor who doesn't do stealth will lose customers. So they all do it. Whether or not stealth really is better or not is irrelevant if you want to sell personal firewall software.
Jason
K
Keith
Yes but would ,should there be any difference in theory or practice assuming no flaws in OS
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.