Re: Cannot Stealth port 113
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Cannot Stealth port 113

From: Greg Hennessy <me@privacy.org>
Date: Fri Dec 23 2005 - 11:26:12 CET

On Thu, 22 Dec 2005 23:00:41 GMT, Leythos <void@nowhere.lan> wrote:

>> >Any help changing port 113 from Closed to Stealthed would be greatly
>> >appreciated.
>> >
>>
>> You shouldn't 'stealth' 113/tcp period.
>
>Why, it won't make any difference to most home users, and little if any
>difference to corporate users.

The last time I looked, home and corporate users still have to send email
and find time to use FTP.

I personally have debugged half a dozen odd instances for customers
suffering timeouts on outbound mail because they were blackholing ident
rather than sending back an RST.

Stealth is a complete and utter waste of time if the upstream hop doesnt
filter icmp unreachables.

greg

-- 
"Access to a waiting list is not access to health care"
Received on Fri Dec 23 20:08:54 2005