-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 04 Apr 2000 at 20:07 +1100, Alexander Else <[EMAIL PROTECTED]> wrote:

> >The characteristics of your IP stack will give away far more
> >information than denying or rejecting packets.  Check out queso, nmap,
> >etc and see what they tell you.  *Any* response from your system gives
> >away information about it.  You can't pretend to be a Windows box even
> >if you *can* make Linux crash at random times.  The IP stacks are just
> >too distinctive.
> 
> I did cover that point already (search for 'fingerprint' in a prior
> email).  Here I'm going on the hope that they run fast scans across
> their ip pools, pick up some obvious 'servers' *snicker*, and maybe flag
> some likelies for further investigation.  I'm hoping that my suggestions
> might avoid being tossed into the 'likely' basket.

  One quick question that puzzles me from the first mention of 
fingerprinting, WHY would Optus be doing this? Do they prohibit you 
from using the OS of your choice on their network? What other use would 
they have of any fingerprint?
  I would have thought that O@H would just do a port scan on known 
server ports to determine firstly if they were open, then to see if 
those ports were active.
  Just because you can run a server, doesn't mean you do. If they want 
to make that claim, ask if they've raped anyone.....after all, if 
they're male they are able to rape a female....it doesn't mean they do 
however.  (My apologies to anyone offended by my example, no offense is 
intended)
  Unless O@H is going to tell you what OS you can and cannot use on
their service, they have no right to fingerprint you, a simple portscan
is sufficient to tell them if you are running servers.

> firewalling policies boring?!  yeah, ok.  I think I've made my point
> anyway.

Not at all, an effective firewall is something that a lot of people 
don't know how to implement, and while I hope I have a secure one, I'm 
always open to suggestions as to what others consider a secure 
firewall.

David Mudford


-----BEGIN PGP SIGNATURE-----
Version: PGP 6.0.2 -- QDPGP 2.60 
Comment: Please verify this signature.  http://www.pgpi.com

iQA+AwUBOOk0BpZb9oayhFBBEQIqjACfcrupJ+abQ5cAFgDDvHZJZ33DGtkAmOIg
IEYYjck/o1JsSAcLE+4wjE4=
=q1Pd
-----END PGP SIGNATURE-----
PGP Key Block available at:
http://aussie.mine.nu/aussie/pgp_key.txt
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to