Re: What is this?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: What is this?

From: Moe Trin <ibuprofin@painkiller.example.tld>
Date: Wed Sep 28 2005 - 21:50:05 CEST

In the Usenet newsgroup comp.security.firewalls, in article
<fAe_e.147189$dP1.504096@newsc.telia.net>, Anders wrote:

>Moe Trin wrote:

>> At my home, I really don't see that much UDP on any of my ISPs (I have
>> three),
>
>Lucky You, I have to go to a friend and use his conection to see my
>network from the outside.

One of then isn't that much of a benefit, as they block a most traffic
that isn't "normal". The second has a very restrictive AUP, so I can't
(for example) use nmap to scan my other addresses.

>Moe, one's again you forced me too read, this time about DNS and
>traceroute, and I stumble up on this RFC<B4>s 1034,1035 and the older one's
>882,883 I have not been able to read them yet, but as soon as I get time
>for it I will.

RFC0882 and 0883 are obsolete - not worth reading except for historical
reasons. For gaining understanding of DNS, the DNS-HOWTO has a lot of
good information:

-rw-rw-r-- 1 gferg ldp 91563 Dec 23 2001 DNS-HOWTO

As you are looking at RFCs, you may want to scan RFC1180

  1180 TCP/IP tutorial. T.J. Socolofsky, C.J. Kale. Jan-01-1991.
       (Format: TXT=65494 bytes) (Status: INFORMATIONAL)

which is also a good read.

>One thing I read about was that it is common that someone who want to
>figure out about a systemcofiguration can make use of traceroute -S udp
>p53, so for time being I happely block that one.

What version of traceoute? I don't recognize the options from either
the original Van Jacobson (LBL) version, Olaf Kirch's re-written version,
or the TCP version from Michael Toren.

        Old guy
Received on Thu Sep 29 20:11:10 2005