At 17:16 04/04/2000 +1000, John Clarke wrote:
> > I think that this is where we differ on our opinions of what people may
> > hope to gain from this discussion.  You're suggesting hiding, I'm
> > suggesting hiding within a crowd.
>
>The characteristics of your IP stack will give away far more information
>than denying or rejecting packets.  Check out queso, nmap, etc and see
>what they tell you.  *Any* response from your system gives away
>information about it.  You can't pretend to be a Windows box even if you
>*can* make Linux crash at random times.  The IP stacks are just too
>distinctive.

I did cover that point already (search for 'fingerprint' in a prior 
email).  Here I'm going on the hope that they run fast scans across their 
ip pools, pick up some obvious 'servers' *snicker*, and maybe flag some 
likelies for further investigation.  I'm hoping that my suggestions might 
avoid being tossed into the 'likely' basket.


>Now, I think we've discussed this topic to sufficient detail to bore the
>crap out of most people.  I know there's been bugger all else list traffic
>today, but I think we should keep any future discussion in private email.

firewalling policies boring?!  yeah, ok.  I think I've made my point anyway.


--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to