Snort mailing list archives

Re: Re: Off topic: Thousands of traceroutes ?


From: skill 's <skill2die4 () yahoo com>
Date: Mon, 13 May 2002 12:13:53 -0700 (PDT)

hi Tudor :

* someone is MAPPING your network , ie trying to find
out where your routers are , where your machines are
... and this is done by using traceroute as a tool.
This is evident as the TTL=1.(read about FIREWALK
technique)

* Source IP addresses are changing , but that could be
a add-on of a MAPPING software, where it sends packets
from various IP's so that you cant NARROW_DOWN on the
culprit.(Same methodology is used by NMAP's DECOY
technique)


what you should do:

* deny all packets with TTL=1 , TTL=2 ... i guess that
would solve your problem.


Pro/Cons :

* No one would be able to MAP your network using
traceroute and same goes for you. You wont be able to
do TRACEROUTE to your machines.


hope , this helped

skill2die4

PS : this was in SANS webcast 2 weeks back , you can
more details on this by going to www.sans.org

__________________________________________________
Do You Yahoo!?
LAUNCH - Your Yahoo! Music Experience
http://launch.yahoo.com

_______________________________________________________________

Have big pipes? SourceForge.net is looking for download mirrors. We supply
the hardware. You get the recognition. Email Us: bandwidth () sourceforge net
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: