sygate and shields up

Sep 08, 2005 42 Replies

Let's assume that this is true (even if it isn't). If they have half a brain they will already know that

82-70-237-22.dsl.in-addr.zen.co.uk is probably a home dsl user (could be business but makes little difference). They will also know that adjacent IP addresses are also users of the same ISP and they will know that an exploitable PC is very likely to be found in this range because a large group of 'stealthed' PCs indicates a large group of Windows users who thought they were safe behind their personal firewall but happily accepted everything Internet Explorer offered them.

They will know all this (and more) even if your computer is behind an event horizon, never mind a personal firewall.

Jason

I was in fact unable to know that you thought I would think that you think this.

Such as?

Yup and either it's exploitable or it's not.

Assuming your computer is not exploitable, can you think of a reason to care about who (world or otherwise) knows your IP address? (I'm not saying there is no possible reason whatsoever).

I don't recall saying anything at all about unix anything.

I think you'll find that it's necessary to have an IP (or IP range) _before_ doing a port scan.

Many home NAT routers appear as 'stealth' to shields up. The vendors would never be able to sell them otherwise. People would return them claiming that they weren't stealth.

I don't recall saying anything at all about unix anything. It may be true that not all the customers of

formatting link
Windows but I think we can safely assume that most of them do.

What makes you want to be safe from port scans? What harm can a port scan do to you?

Jason

Hi Jim, James, the poster, was concerned about a test of his Sygate at GRC that show his ports "Closed". He was wondering why the ports were not called "Stealthed". I suggested he do a test at the Sygate website where he would also find his ports "Blocked" (closed). I was trying to point out that Stealth is advertising nonsense. Most any firewall worth a flip will block/close ports. Casey

On the other hand

formatting link
port-scan distinguishes brtween closed and stealthed.

I like that --- protocol injuring. :)

Duane :)

Please first read RFC 792 and try to understand it. Then you'll see, that this is just nonsense. This is not the way, the TCP/IP network family is working.

If a host is not there, then you get a message from a router before: the message, that a packet to this host cannot be routed (ICMP Destination Unreachable with code 0, net unreachable, or code 1, host unreachable.

If a host is there, and only there is no process listening at the port you wanted to communicate with, you get a message: ICMP Destination Unreachable with code 3 or a TCP RST (see RFC 793).

If you're getting nothing, then you know: there definitely _is_ a host: A Windows box with a protocol injuring "Personal Firewall" which fools it's user feeling "stealth".

No. The system you communicate with has your IP address, of course - you're communicating with it. But it cannot "read ... anything else your security settings allow". This is just wrong.

This is monkeyshines. The reason why not using ActiveX is completely different - it's the design flaws in ActiveX. This has nothing to do with "mobile code" or "scripts".

BTW: I never told that.

Please, before you're starting with polemics, *PLEASE* read the RFCs. They're in English. You can understand that, if you try.

The RFCs

formatting link
are the official standards of the IETF, the Internet Engineering Task Force,
formatting link
Yours, VB.

What problem are you having with the Windows-Firewall?

Yours, VB.

If you mean with that, that sometimes your computer is not connected and sometimes it is, yes even if your computer is "stealthed", one can detect that.

That is, because if you're not online, the router of your provider sends a ICMP Destination Unreachable message, usually with code 1 (host unreachable). When you're connected, then it doesn't.

You're guessing wrong.

Yours, VB.

Sorry, this is all nonsense.

No-one would use ICMP echo (this is what your PING command does) to find out wether a host exists or not.

ICMP echo is just for testing purposes in own setups. Everyone knows, that most people try to "hide" their PCs by filtering ICMP echo, so no-one will use it for such cases.

A much better probe is using nmap -sS -P0 to scan, just sending TCP SYN to different ports. Usually, one get's back information like ICMP destination unreachable with code 0 or 1, which means there is no host, or ICMP destination unreachable with code 3, TCP RST or just nothing, which means, that there _is_ a host.

This is why nmap is showing a host to be there also if there is no reply.

BTW: because there will be no help for security at all with "hiding" a PC or other host, even if this would be possible, this complete discussion is ridiculous anyway.

Yours, VB.

That's right, because it's not helping to make a computer more secure at all.

*ROTFL* - how should routing work _without_ having this IP? Please, *PLEASE* first try to understand the concepts you're talking about!
*sigh*

The next misunderstanding. "Hackers" (you mean crackers, see the Jargon File), are not trying to get anybodies IP. They're just scanning networks for connected boxes, the IPs they have already.

Yes, and that tells an attacker, that there definitly _is_ a host, otherwise he would have got back an answer, as I stated already.

This is wrong, unfortunately. Could you *please* read the RFCs now, before you're continuing to argue? That would help to have a sensible discussion, thanx!

No, it hasn't.

I don't know most UNIX users. Usually they don't do it, because this is crippeling your TCP/IP implementation, wrong undefined behaviour, which does not help at all.

The problem is, that anonymity in the Internet cannot achieved this way at all. Better methods you'll find in the Tor project and in the AN.ON project. Both of them are good ideas to try to reach anonymity in the Internet.

Yours, VB.

Ok, I'll try to explain.

We're not talking about the "real world", the world where the pizza man comes from ;-) We're talking about computers, about a special case of computers: about deterministic machines. But let us compare anyway:

Here you have three classes of methods for improving security against the incidence of an event you want to avoid.

[A] You can make it impossible for an event to happen, already in theory. [B] You can make it unlikely for an event to happen, so unlikely, that you can say, it will not happen in practice. [C] You can make it unlikely for an event to happen, but the likelihood is not small enough, that you can be sure, that it will not happen in practice. It will be seldom, though.

I think, it's obvious, why to prefer methods of class [A] to methods of class [B], and why to prefer methods of classes [A] and [B] to methods of class [C], OK?

There is no method of [A] or [B] to make a soldier or a cameleon not being detected. There is only a method of [C]: camouflage. So, because there is no other way, soldiers and chameleons are using methods of [C].

Believe me, if a soldier or a chameleon had the option to find methods of [A] or [B], they would do it immediately and not using camouflaging any more.

Now there are differencies between deterministic machines and the pizza man universe:

With deterministic machines there often are possibilities for methods of [A] or at least [B], for most of the cases, so why using methods of [C] at all?

Another reason is: Many of the events you want to avoid are secrets detected by an attacker. Methods of [C] do not help here at all, because in the deterministic descrete world of computers, all states are countable. Usually, a method is in [C] and not in [B], because it is possible also in practice to just "try out" every combination (beside cleverer ways, which will be prefered by most attackers). This is called "brute forcing".

Brute forcing only is not possible if the secrets are protected by methods of [A] or a least of [B] (by definition).

So this is the reason, why people say: "Don't use security by obscurity, it will not work".

To be exactly, they should say: "Don't use security by obscurity for most of the cases, because there are much better methods to secure - in most cases, security by obscurity will not work, though, only in a few ones it could work anyway."

Clear now? ;-)

Yours, VB.

I tried out

formatting link
- the results were useless. You can find out more on this topic in

Yours, VB.

No, it isn't.

They do it because, then people _feel_ more secure, when they're buying such products, though they're not more secure. This is fooling people.

I'm looking forward to the explanation ;-)

Yours, VB.

Apparently, your O/S is masking what's happening.

When you 'ping' an address that doesn't have a computer, the last working router your ping passes over trying to reach the address will discover "you can't get there". The _router_ sends an error message back to you.

When you 'ping' a working address, this error doesn't happen, because the last router is able to send the packet on - it doesn't make one bit of difference if the destination is stealth, closed, or has it's legs wide open. It doesn't make ANY difference no matter what the operating system is on the destination. The router did it's job, and forwarded the packet.

If you 'ping' a working address and the destination is open, you should get a response back. If the destination is closed, you will also get back a response, but it will tell you that it's closed.

If the destination is stealthed, then you won't get a response back.

Now, re-read what I've just written. The ONLY time you don't get a response back is when it's stealthed. So why do you feel it's so hard to detect stealthed computers?

Old guy

Possible, but only under exceptional circumstances.

0792 Internet Control Message Protocol. J. Postel. Sep-01-1981. (Format: TXT=30404 bytes) (Obsoletes RFC0777) (Updated by RFC0950) (Also STD0005) (Status: STANDARD)

ICMP doesn't have ports. An ICMP Echo Request (called a 'ping' based on the original program used) is a Type 8 Code 0. The ICMP Echo Reply is a Type 0 Code 0. The port 7 you are thinking of:

echo 7/tcp Echo echo 7/udp Echo # Jon Postel

(Jonathan Postel died in 1998, but you'll find his name nearly everywhere in Internet documents.) Notice that the '7' is referencing TCP and UDP. The document that defines that is

0862 Echo Protocol. J. Postel. May-01-1983. (Format: TXT=1294 bytes) (Also STD0020) (Status: STANDARD)

While it is a standard, no one uses this service.

When you attempt to contact a computer that does not exist (is turned off, not plugged in, never unpacked - doesn't matter), the last working router sends an error message back "I can't get there".

When you attempt to contact a computer that is connected, and open or closed, you will get back a response from that computer (either a "welcome", or a "go-away" message).

When you attempt to contact a computer that is stealthed, there is no response.

So, the quite obvious difference is that error message from the router. Your premise fails.

Correct.

Nope. The only thing stealth MAY buy you is preventing O/S fingerprinting, but only if no ports are open, and ALL OTHER PROTOCOLS (there's another hint - there is more than ICMP, TCP and UDP) are set to remain silent. Nearly everyone using 'stealth' is quite unaware of the other problem, so stealth fails.

TCP/IP Illustrated Volume 1 - The Protocols. W.Richard Stevens 1994,96 Addison Wesley, ISBN 0-201-63346-9, 576 pgs, US$LOTS

Try to find a copy in a technical library. The book is normally used as a textbook in college or university networking classes. I think I paid about US$55 for my copy in 1994. It's a bit old, but it profusely illustrated, and understandable because of that and the many examples it contains.

Old guy

ok- if you're talking about competing options of which A is superior to B which is superior to C.

But In the stealth case. C=stealth, is not inferior to B=Closed (in terms of security offered). Infact, C matches the security offered by B (if it's Stealthed then it's not Open. It is closed), it just makes it a tiny amount more difficult to find out if the IP exists on the internet (you said in a post. nmap with the switch -p0).

In your case, you would use many intelligent techniques for securing your system. A cracker intelligent enough to get through your system would not be put off by a 'Stealthed port' or fooled into thinking that there's no comp or router with that IP.

Perhaps for the average user, that little obscurity might put off a cracker that could break into their system.

Not always? For example, in an ethernet environment if the end device is recently[1] powered down (or powered down and has a static entry in the ARP table) the router will have an ARP entry. It has no need to send an ARP request (which would result in the router responding as in your examples). It encapsulates the PDU and sends it on its way. Exactly the same would happen with a 'stealthed' device. IMO the only way of really telling any difference (bar trying to elicit responses via crafted packets) is to have access to the layer 2 devices and trace the port the device is patched to and see whether one can detect a MAC there (or ascertain how old the ARP table entry is on the router if it is not a static).

[1] 'recently' being a value less than the expiration period of the cached entry in the router's ARP table. I think the default value for Cisco IOS is about 4 hours?

If a hacker broke into average someone's computer with any type of filter/PFW active on the machine and configured properly, the average someone contributed in someway that lead to the compromise of the machine by the user clicking on something that introduced the compromise. So closed port or stealthed ports it's over.

If one wants a machine to be stealthed, then one puts the machine behind a cheap NAT router with all ports closed by default and unsolicited inbound traffic never reaches the machine -- that's stealth.

Duane :)

Sorry, no.

The point, that a router detects somewhat later, if a device is just switched off, has nothing to do with "stealthing". The WAN connections don't use ARP at all usually anyway, but some point2point protocol.

It's enough to look at the ICMP messages. Just try it out, please. Or better: read the RFCs yourself.

Yes. But: so what?

Yours, VB.

In terms of security, sending nothing is not superior to sending TCP RST, and sending TCP RST is not superior to sending nothing. It just doesn't matter.

In terms of networking, sending nothing in this situation means violating protocol, and that means one does not support the free Internet any more, but disturbing free communication.

It's just b0rken to send nothing in this situation, anybody who is able to read the RFCs can understand that. And it's completely useless.

No. It doesn't. It's ridiculous to argue, that -P0 as an option in nmap will make it more difficult to scan "stealthed" hosts. It does not do it at all. Usually, when I'm scanning, I'm typing nmap -sS -P0 automatically without knowing what's goin' on, or on my laptop there is an alias nmap='nmap -sS -P0' already in my .zshrc - so what?

Even if "stealthing" would bring obscurity (which it does not as I stated already), this would not help at all. Any script-kiddy tool can handle such easy things, so even not pupils who are trying out "cracking boxes" out of the school network will be influenced by such ridiculous "security".

"Stealthing" is, what it is: an idea, perhaps from Mr. Gibson, which sounds good, everyone is believing in, the manufacturors of "security" software like the "Personal Firewalls" can make advertizing with and money is coming in with.

It's a typical placebo.

Yours, VB.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required