Wilders Security Forums  

Go Back   Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 26th, 2003, 04:25 PM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default LooknStop Fails Test

Activated LooknStop and imported the Advanced RuleSet. Tested against PC-Flank - even on QuickTest, it failed to stealth Port 80.

Ruleset attached, what can be done to stealth this port??

Attached Images
 
  #2  
Old January 26th, 2003, 04:27 PM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default Re:LooknStop Fails Test

See PCFlank Test Results below:
Attached Images
 
  #3  
Old January 27th, 2003, 04:04 PM
Klaude Klaude is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 17
Default Re:LooknStop Fails Test

Quote:
what can be done to stealth this port??

Create a rule to block port 80.
Attached Images
 
  #4  
Old January 27th, 2003, 04:11 PM
Klaude Klaude is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 17
Default Re:LooknStop Fails Test

In your "Internet Filtering List", looks like...
Attached Images
 
  #5  
Old January 27th, 2003, 04:25 PM
Frederic Frederic is offline
LnS Moderator
 
Join Date: Jan 2003
Location: France
Posts: 4,354
Default Re:LooknStop Fails Test

Would be interesting to select the http://www.looknstop.com/Fr/images/faq_look.gif as well to see if the packets are seen and not blocked, or not seen at all.

Frederic
  #6  
Old January 27th, 2003, 09:20 PM
SKA SKA is offline
Regular Poster
 
Join Date: Aug 2002
Posts: 151
Default Re:LooknStop Fails Test

Where shud such a rule(Block 80) appear be in the list of advanced rules ?

SKA
  #7  
Old January 27th, 2003, 11:16 PM
Klaude Klaude is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 17
Default Re:LooknStop Fails Test

There's no rule to block the port 80 in the advanced rules set I think. So you need to create one if needed, and you put it "at the top" of the list if you wish.
  #8  
Old January 28th, 2003, 12:49 AM
MickeyTheMan's Avatar
MickeyTheMan MickeyTheMan is offline
Global Moderator
 
Join Date: Feb 2002
Posts: 1,016
Default Re:LooknStop Fails Test

Darksy, any reason why you deactivated rule 4 & 5 ?
  #9  
Old January 28th, 2003, 12:58 AM
MickeyTheMan's Avatar
MickeyTheMan MickeyTheMan is offline
Global Moderator
 
Join Date: Feb 2002
Posts: 1,016
Default Re:LooknStop Fails Test

Quote:
quoting: Klaude link=board=13;threadid=6720;start=0#45120 date=1043727378]
There's no rule to block the port 80 in the advanced rules set I think. So you need to create one if needed, and you put it "at the top" of the list if you wish.
http://itsec.commontology.de/firewalls/lns/block%2080%20outbound.gif

That rule is really to prevent EDexter, spyblocker and similar apps to send out info, which they shouldn't in the first place

BTW, That site is a good place to learn about rules http://itsec.commontology.de/firewalls/lns/lns-rules.html
  #10  
Old January 28th, 2003, 01:15 AM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default Re:LooknStop Fails Test

Added rule for Port 80 - still, LooknStop is failing to stealth port on PCFlank's QuickTest. See below
Attached Images
 
  #11  
Old January 28th, 2003, 01:16 AM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default Re:LooknStop Fails Test

See below
Attached Images
 
  #12  
Old January 28th, 2003, 01:17 AM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default Re:LooknStop Fails Test

Still failing to stealth on QuickTest of PCFlank...see test below:
Attached Images
 
  #13  
Old January 28th, 2003, 08:37 AM
Klaude Klaude is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 17
Default Re:LooknStop Fails Test

Weird.
Like Frederic said, select the ! to see if the packets are seen and not blocked, or not seen at all.
Check your logs after...
Did you try the test elsewhere ?
Use the "Advanced port scanner" at PCFlank just to scan ONE port, 80 in your case. Same result ?
Attached Images
 
  #14  
Old January 28th, 2003, 01:28 PM
darksky darksky is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 33
Default Re:LooknStop Fails Test

Hi,

I selected ! and re-ran the test...

My stats are below:

Thanks....
Attached Images
 
  #15  
Old January 31st, 2003, 02:11 PM
Vampirefo
 
Posts: n/a
Default Re:LooknStop Fails Test

Post your logs, I am guessing your ISP is blocking port 80, meaning your port 80 is not being scanned, your ISP's port 80 is being scanned instead of yours.


Look in your logs, do you see a scan on port 80? I think not.
 

Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:42 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums