Firewall Wizards mailing list archives

RE: Block / Monitor PORTSCAN/QUESO/NMAP/ETC...


From: jussi.jaakonaho () nokia com
Date: Fri, 5 Nov 1999 11:09:41 +0200

It IS possible to protect yourselves from these type of
"attacks" (personally i dont consider them attacks but thats another
point) by modifying your TCP/IP stack. Now I realise this is 
not for the
hi,
that is true for NT, too.
i tried mostly these settings to some of my machines:
http://support.microsoft.com/support/ServiceWare/NTServer/Nts40/371KROAA.ASP

basically they are for protecting against syn flooding (DoS-attacks).
it was a bit surprise when i was running nmap against them,
it did not recognise my servers. i even took 10 fingerprints
and added them to database-->nmap did not recognise servers.
(it (fingerprint) was a bit different each time)


_jussi

"opinions are mine, not my employer's"



Current thread: