Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 17th, 2003, 09:14 PM
I_lack_commonsense I_lack_commonsense is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 44
Default Backtracing Capabilities in Software Firewalls

Is the backtracing feature in software firewalls effective, say if someone was using a proxy?

Ive read in an article that by examining the TTL field in an IP header you can at least tell how many hops this packet has traveled. Though the author also mentioned that this is no longer very effective either.

Thanks again
__________________
The internet is a great way to connect to the net.
  #2  
Old May 18th, 2003, 04:36 AM
JacK's Avatar
JacK JacK is offline
Frequent Poster
 
Join Date: Jun 2002
Location: Belgium -Liège
Posts: 737
Default Re:Backtracing Capabilities in Software Firewalls

Quote:
quoting: I_lack_commonsense link=board=23;threadid=9323;start=0#61048 date=1053220470]
Is the backtracing feature in software firewalls effective, say if someone was using a proxy?

Ive read in an article that by examining the TTL field in an IP header you can at least tell how many hops this packet has traveled. Though the author also mentioned that this is no longer very effective either.

Thanks again

Hello,

I should not recommend using this kind of tool : if it's really an attack nobody is stupid enough to do it with is real IP.

I it's just a probe to find weak machines the only result is that the scriptkiddie now knows for sure there is someone at your address

Better to use online tool like VisualRoute Demo from their site : the potential attacker will not see it's coming from you IP

Rgds,
  #3  
Old May 18th, 2003, 06:23 AM
Patrice Patrice is offline
Frequent Poster
 
Join Date: Apr 2003
Location: Antarctica
Posts: 571
Default Re:Backtracing Capabilities in Software Firewalls

Hi JacK,

is VisualRoute similar to NeoTrace Pro? It looks quite the same. Any knowledge about that?

Regards,

Patrice
__________________
I know nothing except the fact of my ignorance. (Socrates 470-399 bc)
  #4  
Old May 18th, 2003, 12:14 PM
I_lack_commonsense I_lack_commonsense is offline
Infrequent Poster
 
Join Date: Jan 2003
Posts: 44
Default Re:Backtracing Capabilities in Software Firewalls

I was wondering because when people get something in their firewall log or get an alert that they are being port scanned or pinged (numerous amounts of time), the first instinct is to usually check the log and the IP of the intruder. But as Jack mentioned, a lot of people today aren't going to conduct an attack from their own IP. So how effective are logs and the backtracing feature in firewalls? Are they only effective in telling the user of the origin of the last packet destination? Or are they effective enough to offer as proof to an ISP if someone is in violation of their ISP's TOS?

Thank you again
__________________
The internet is a great way to connect to the net.
  #5  
Old May 18th, 2003, 01:47 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:Backtracing Capabilities in Software Firewalls

Thanks for the info on VisualRoute Demo
Evern though I know I shouldn't be using the back trace funtion in Sygate, I still do. ooppssss.
I will give Visual Route a try

con
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:00 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums