Wilders Security Forums  

Go Back   Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 24th, 2003, 06:59 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default UDP non-Stealthed

Hello,To all

Well here i go again back to L&S ran a test
on it all was great but for this one here

UDP non-Stealthed Huh any help at all please

Good luck

Hey,Paul
  #2  
Old October 24th, 2003, 07:51 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

You can E-mail the rule-set to me and i can take a look for yea and e-mail back with the information on the culprit rule if you like...
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #3  
Old October 24th, 2003, 08:26 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hi, Phant0m

Thanks where do i send it or how i don't see
an E-Mail anywhere let me know please but i
am safe for now Yes/No & do i copy &
send you the rules

Thank you
  #4  
Old October 24th, 2003, 08:32 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

My E-mail is in my wilders profile (Phant0m@wilderssecurity.info)...

You can send me the entire rule-set file and i'll take a gander at it for yea...
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #5  
Old October 24th, 2003, 08:46 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hi,Phant0m

Ok thanks send it now by AAPlus

on it's way

Good luck
  #6  
Old October 24th, 2003, 09:53 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

Where did you get "UDP non-Stealthed" from?
I checked the rule-set and there is no rule except for the DHCP rule which doesn't specify the DHCP server.
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #7  
Old October 24th, 2003, 10:34 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hi,Phant0m

It was at PC Flank


Packet' type Status
TCP "ping" stealthed
TCP NULL stealthed
TCP FIN stealthed
TCP XMAS stealthed
UDP non-stealthed

i hope this helps you or i should say help me hehe

Good luck
  #8  
Old October 24th, 2003, 10:41 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

The EnhancedRulesSet.rls (Default rule-set) you've sent me blocks these types of packets, "Block : All other packets" rule in the rule-set at the very bottom catches these packets...

Regards,
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #9  
Old October 24th, 2003, 10:41 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hey,Phant0m

I also did a scan at Shields-up & the only
thing i got was 113 IDENT which i think is
from using Avast for scaning my E-Mail

then all is ok

Thanks
  #10  
Old October 24th, 2003, 10:43 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

For the identd rule have you configured the Identd Application for it?
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #11  
Old October 24th, 2003, 10:45 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Also perhaps you should configure the Identd rule with the specific E-mail server…
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #12  
Old October 24th, 2003, 10:55 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hi,Phant0m

I have no idea how to do this hehe
any help with that please

Good luck
  #13  
Old October 24th, 2003, 11:00 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Do you have an identd rule Enabled?

In EnhancedRulesSet.rls the rule "TCP : Authorize Identification", is this Enabled or Disabled? Or did you create additional rules for Identd purposes?
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #14  
Old October 24th, 2003, 11:11 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

hi,Phant0m

I think it is Disabled as far as i can tell
sorry not good at this

Good luck
  #15  
Old October 24th, 2003, 11:20 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

What type of connection you have?
You have Network?
And are you using Router?

__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #16  
Old October 24th, 2003, 11:28 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

I am using Cable & yes i'm on a Router

Good luck
  #17  
Old October 24th, 2003, 11:41 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Maybe the router is listening on identd port, or possibly another computer with identd listening?

Otherwise the Online web-scan is displaying false reading, which is very common…
Try re-doing the Online Scan few times or try alternative Online web-scans…
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #18  
Old October 25th, 2003, 12:19 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re:UDP non-Stealthed

Quote:
quoting: AAP link=board=13;threadid=15377;start=15#msg95966 date=1067052480]
I am using Cable & yes i'm on a Router

Unless you have forwarded any traffic through to systems behind the router, it is the router being tested by the online scans.

The port 113/Ident showing as closed is normal for a number of different routers. It is also not unusual for routers to have the UDP results you did. As long as nothing is showing up in your LnS logs on the system behind the router, nothing is getting through.

Depending on your router, there are usually workarounds to stealth port 113 if "stealth" is something you feel you need. As for the UDP, check your configuration options for the router and if you are runnng the current firmware.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #19  
Old October 25th, 2003, 12:10 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hey,Phant0m & CrazyM

Ok going nut's here have no idea why this is going on
i am gething the same thing for all 7 puters all of them
give me the same thing how can this bee here it is again

on all 7 @ PC Flank


Packet' type Status
TCP "ping" stealthed
TCP NULL stealthed
TCP FIN stealthed
TCP XMAS stealthed
UDP non-stealthed

& @ Shields Up all 7 i get that
113 IDENT

oh why did i have my Boy's add this Router thing
should i just remove it or is there a way around this

now i think the UDP is a F/P you tell me guy's

Thanks have a good one
  #20  
Old October 25th, 2003, 12:24 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

Hey AAP

Is Look ‘n’ Stop Installed on all the Network Computers?
If so you can activate the EnhancedRulesSet.rls rule labelled "TCP : Authorize Identification" and configure block & warn Flag on-it. And re-run the online web-scan and keep an eye on that rule display in Look ‘n’ Stop’s Log screen, if you see them then you are getting the Ident packets otherwise you arent...

You may just need to access the Router and check out its configurations and make modifications...
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #21  
Old October 25th, 2003, 12:33 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

AAP you using Windows XP on any of the Network Machines?
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #22  
Old October 25th, 2003, 12:36 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,326
Default Re:UDP non-Stealthed

I suppose just be easier to Forward those ident packets to Non-existing IP in your Network…

There is a bit of Information about Routers at http://www.fasttrackhelp.com/development/ftfakes/kanat/kanaten.html. For Port Forwarding Info you should visit http://www.fasttrackhelp.com/development/ftfakes/kanat/portfwen.html.
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
  #23  
Old October 25th, 2003, 12:55 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hi,Phant0m

No i just have L & S on 3 of the puters i think
the problem is on my end like you just said
i may need to check the Router i need to get this
done before they go & install some other toy

each time the add something it's more work
for dad not good well you have a great weekend
i am on my way to that link you posted then
have a look at the config of that Router thing oh boy

Thanks for all your time & help

Hey,Paul
  #24  
Old October 25th, 2003, 10:19 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hey,Phant0m

I got it fixed i just had a look at that link
you posted for me & did as was said &
all is good now you have a great weekend

& once again thanks for all the help

Good luck
  #25  
Old October 25th, 2003, 10:30 PM
AAP AAP is offline
Regular Poster
 
Join Date: Jul 2003
Posts: 117
Default Re:UDP non-Stealthed

Hey,Phant0m

There is one thing i forgot to add why am i
not gething a Logfile when i look at the option
for Log in L & S

Thank you
 

Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:38 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums