Moe Trin wrote:
> In the Usenet newsgroup comp.security.firewalls, in article
> <fAe_e.147189$dP1.504096@newsc.telia.net>, Anders wrote:
>
>
>>Moe Trin wrote:
>
>
> One of then isn't that much of a benefit, as they block a most traffic
> that isn't "normal". The second has a very restrictive AUP, so I can't
> (for example) use nmap to scan my other addresses.
>
I make use of callcontrol, this way I can have all my portīs in
dropp/block mode even the more common one like ftp, mail and web.
But I do realise that if I want to make use of my one mail/web and ftp
server I do have to open up a litle.
>
>
> RFC0882 and 0883 are obsolete - not worth reading except for historical
> reasons.
I do like history, but I will read the more current ones first.
>For gaining understanding of DNS, the DNS-HOWTO has a lot of
> good information:
>
> -rw-rw-r-- 1 gferg ldp 91563 Dec 23 2001 DNS-HOWTO
>
> As you are looking at RFCs, you may want to scan RFC1180
>
> 1180 TCP/IP tutorial. T.J. Socolofsky, C.J. Kale. Jan-01-1991.
> (Format: TXT=65494 bytes) (Status: INFORMATIONAL)
>
> which is also a good read.
>
Itīs downloded, and I will not only scan them.
>
> What version of traceoute? I don't recognize the options from either
> the original Van Jacobson (LBL) version, Olaf Kirch's re-written version,
> or the TCP version from Michael Toren.
>
> Old guy
Well, in this book (Hacking Exposed, Fourth Edition printed in 2003 by
Stuart McClure, Joel Scambray, and George Kurtz), I did find this about
locking traceroute to use only one particular port of youīre own desire.
Traceroute 1.4a5
(ftp.cerias.purdue.edu/pub/tools/unix/netutils/traceroute/old) is what
they clamed should work, they also declare that it is a modifyed verion
of traceroute, made by Michael Schiffman 1997.
(http://www.hackingexposed.com/) is the home page of the book, my copy
is in Swedish and it is a litle difficult for me to translate it back in
to English.
Anders
Received on Thu Sep 29 20:11:13 2005