Patrice
April 23rd, 2003, 05:07 PM
Hello everyone!
During the last time there have been several questions about the rules IP: Fragment Block, TCP: FIN Flags,... These rules are not enabled by default in enhanced mode. I would like to show you why such rules should be enabled all the time. For further information about the questions see:
http://www.wilderssecurity.com/showthread.php?t=8613
http://www.wilderssecurity.com/showthread.php?t=8690
On of my principles still is:
YOU SHALL KNOW HOW HACKERS ATTACK, SO THAT YOU CAN DEFEND YOURSELF!
Now let's see, what this means in reality. First of all, hackers use so called port scanners to find open ports and unprotected computers. Examples of such tools are:
Superscan:
http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/freetools.htm
Nmap:
http://www.insecure.org/nmap/index.html
Let's look especially at the latter one, which is of more importance. If you scan an IP-range you'll find a lot of open, unprotected computers, sigh... Yes, unfortunately this is true! :'(
With the Nmap tool you can do special port scans, as you see in the following image:
http://www.insecure.org/nmap/images/nmapfe.gif
As you see you are able to use the SYN Stealth, FIN Stealth,... method to find open ports. Most popular firewalls/routers answer to such packets. And this means that you're system has been compromised!! Yes, you aren't stealth anymore! Now they know that your computer is up and running! :o
If you enable the rules IP: Fragment Block, TCP: FIN Flags,... you will be safe of such attacks (even though there's no 100% security). If you don't enable them you aren't safe at all!!!
If you wanna know how hackers attack systems, read the following posts of a hacker (translated into several different languages):
http://www.insecure.org/nmap/nmap-fingerprinting-article.html
So, when you have read this article and you still don't think security is important, I can't help you! If you say to yourself, please help me to make my system more secure you are at the right place and at the right forum. 8)
First I suggest that you enable the above mentioned rules (you use enhanced mode, don't you) and secondly that you consider putting a good router in front your computer (if you have more than one computer accessing the net).
There are certainly more methods of making your computer more secure, but if you read this, you are already at the right place. Go ahead and read in the other forums (TDS-3,...). If you wanna test your own system and its security go for example to PC Flank and GRC (ShieldsUP) and test it thoroughly:
http://www.pcflank.com/
http://grc.com/default.htm
If you have further questions, don't hesitate to ask! ;)
Best regards!
Patrice
During the last time there have been several questions about the rules IP: Fragment Block, TCP: FIN Flags,... These rules are not enabled by default in enhanced mode. I would like to show you why such rules should be enabled all the time. For further information about the questions see:
http://www.wilderssecurity.com/showthread.php?t=8613
http://www.wilderssecurity.com/showthread.php?t=8690
On of my principles still is:
YOU SHALL KNOW HOW HACKERS ATTACK, SO THAT YOU CAN DEFEND YOURSELF!
Now let's see, what this means in reality. First of all, hackers use so called port scanners to find open ports and unprotected computers. Examples of such tools are:
Superscan:
http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/freetools.htm
Nmap:
http://www.insecure.org/nmap/index.html
Let's look especially at the latter one, which is of more importance. If you scan an IP-range you'll find a lot of open, unprotected computers, sigh... Yes, unfortunately this is true! :'(
With the Nmap tool you can do special port scans, as you see in the following image:
http://www.insecure.org/nmap/images/nmapfe.gif
As you see you are able to use the SYN Stealth, FIN Stealth,... method to find open ports. Most popular firewalls/routers answer to such packets. And this means that you're system has been compromised!! Yes, you aren't stealth anymore! Now they know that your computer is up and running! :o
If you enable the rules IP: Fragment Block, TCP: FIN Flags,... you will be safe of such attacks (even though there's no 100% security). If you don't enable them you aren't safe at all!!!
If you wanna know how hackers attack systems, read the following posts of a hacker (translated into several different languages):
http://www.insecure.org/nmap/nmap-fingerprinting-article.html
So, when you have read this article and you still don't think security is important, I can't help you! If you say to yourself, please help me to make my system more secure you are at the right place and at the right forum. 8)
First I suggest that you enable the above mentioned rules (you use enhanced mode, don't you) and secondly that you consider putting a good router in front your computer (if you have more than one computer accessing the net).
There are certainly more methods of making your computer more secure, but if you read this, you are already at the right place. Go ahead and read in the other forums (TDS-3,...). If you wanna test your own system and its security go for example to PC Flank and GRC (ShieldsUP) and test it thoroughly:
http://www.pcflank.com/
http://grc.com/default.htm
If you have further questions, don't hesitate to ask! ;)
Best regards!
Patrice