<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: Port 0 and 1 Shows Closed not stealth Please helo&#x27; in forum &#x27;Wireless Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22929749</link>
<description></description>
<language>en</language>
<pubDate>Sat, 11 Feb 2012 14:09:03 EDT</pubDate>
<lastBuildDate>Sat, 11 Feb 2012 14:09:03 EDT</lastBuildDate>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22945661</link>
<description><![CDATA[antdude posted : <div class="bquote"><small>said by <a href="/profile/1142151" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1142151');">chascent</a>:</small><br><br>Can you run this thru the router??<br> </div>Run what? DenyHosts? No. Linux/UNIX thing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22945661</guid>
<pubDate>Sat, 29 Aug 2009 23:27:54 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22945481</link>
<description><![CDATA[chascent posted : Can you run this thru the router??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22945481</guid>
<pubDate>Sat, 29 Aug 2009 22:31:34 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22944073</link>
<description><![CDATA[antdude posted : <div class="bquote"><small>said by <a href="/profile/334792" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=334792');">SYNACK</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</small><br><br> Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.<br> </div>As long as you forward to a real server you're fine.<br> </div>Yeah, I do. I also use DenyHosts to block brute force attacks.<br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22944073</guid>
<pubDate>Sat, 29 Aug 2009 15:33:39 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943961</link>
<description><![CDATA[jbibe posted : <div class="bquote"><small>said by <a href="/profile/334792" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=334792');">SYNACK</a>:</small><br><br>A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline.  </div>Whether or not a person should use the technique depends on how important "stealth" is to the individual, and the probability of a particular port being scanned or flooded during normal operation. In the case of port 0 and port 1, I cannot remember if I have every seen a log entry showing a scan of these ports. It seems to me that the probability of the ports being scanned is essentially zero. Therefore, the probability of exceeding the limit of the NAT is very, very small.<br><br>Personally, I don't believe that having port 0 and port 1 show closed during a scan test is important -- the device is secure.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943961</guid>
<pubDate>Sat, 29 Aug 2009 15:02:22 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943600</link>
<description><![CDATA[SYNACK posted : <div class="bquote"><small>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</small><br><br> Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.<br> </div>As long as you forward to a real server you're fine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943600</guid>
<pubDate>Sat, 29 Aug 2009 13:34:08 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943349</link>
<description><![CDATA[antdude posted : <div class="bquote"><small>said by <a href="/profile/334792" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=334792');">SYNACK</a>:</small><br><br>Stealth has exactly one advantage:<br><br>It allows relatively clueless users to <A HREF="http://www.dslreports.com/forum/remark,3495752">easily verify</a> with online tools that the firewall software is actually enabled and running. ;)<br><br><b><A HREF="http://www.dslreports.com/forum/remark,3490473">Here's</a> an old discussion that might shed some light on your questions.</b><br><br>A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline. What do you think is a more graceful handling of a stray packet arriving on the WAN side: (1) Having the router return a RST for a "closed" response, then going back to regular work? (2) triggering a flurry of local LAN and router activity, but resulting in a stealth response to the outside viewer? Though so! :D<br> </div>Interesting. So would having one or a few ports be any differences? I only have one port opened for SSH.<br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943349</guid>
<pubDate>Sat, 29 Aug 2009 12:20:49 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943331</link>
<description><![CDATA[SYNACK posted : Stealth has exactly one advantage:<br><br>It allows relatively clueless users to <A HREF="http://www.dslreports.com/forum/remark,3495752">easily verify</a> with online tools that the firewall software is actually enabled and running. ;)<br><br><b><A HREF="http://www.dslreports.com/forum/remark,3490473">Here's</a> an old discussion that might shed some light on your questions.</b><br><br>A very misguided effort for stealth (as suggested elsewhere) is the idea of forwarding a port to a nonexistent or stealthed machine or on the LAN. Since each probe will create a temporary entry in the NAT table of the router while the router tries to ARP or contact the nonexistent machine, it can lead to resource starvation on the router. This creates a vulnerability, because flooding that port can overload the router, knocking the entire LAN offline. What do you think is a more graceful handling of a stray packet arriving on the WAN side: (1) Having the router return a RST for a "closed" response, then going back to regular work? (2) triggering a flurry of local LAN and router activity, but resulting in a stealth response to the outside viewer? Though so! :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943331</guid>
<pubDate>Sat, 29 Aug 2009 12:16:41 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943104</link>
<description><![CDATA[antdude posted : <div class="bquote"><small>said by <a href="/profile/334792" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=334792');">SYNACK</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/853361" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=853361');">Dude111</a>:</small><br><br>...(Which is safer)</div>That's an old myth. ;)<br> </div>It is? How so? :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22943104</guid>
<pubDate>Sat, 29 Aug 2009 11:17:02 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22942402</link>
<description><![CDATA[SYNACK posted : <div class="bquote"><small>said by <a href="/profile/853361" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=853361');">Dude111</a>:</small><br><br>...(Which is safer)</div>That's an old myth. ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22942402</guid>
<pubDate>Sat, 29 Aug 2009 03:18:32 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22941921</link>
<description><![CDATA[Dude111 posted :  <blockquote><small>quote:</small><hr>As stated by SYNACK, closed is as secure as "stealth".<hr></blockquote>I think a CLOSED port can be detected by a port probe AS A CLOSED PORT... A "Stealthed" port is not detected AT ALL.. (Which is safer)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22941921</guid>
<pubDate>Fri, 28 Aug 2009 23:42:37 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22939929</link>
<description><![CDATA[chascent posted : For some reason it does not work. I tried this on a buffallo router that was showing 113 closed not stealth and it worked.<br>Any idea why on DIR-825 it will not work?<br><br>Charlie C]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22939929</guid>
<pubDate>Fri, 28 Aug 2009 16:25:07 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22939677</link>
<description><![CDATA[jbibe posted : I assume that you are referring to scan of the WAN port, that the scan shows all ports "stealth", except port 0 and port 1, and that port 0 and port 1 show closed.<br><br>As stated by SYNACK, closed is as secure as "stealth".<br><br>If showing closed is still a problem for you, try forwarding the two ports to the IP address on your LAN that is not being used by an existing computer.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22939677</guid>
<pubDate>Fri, 28 Aug 2009 15:40:08 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22938977</link>
<description><![CDATA[SYNACK posted : A closed port is equally secure than a stealthed port.<br><br>What dlink router model do you have?<br><br>Why did you post this in the wireless security forum? What router interface (WAN, LAN, Wireless) did you test and how?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22938977</guid>
<pubDate>Fri, 28 Aug 2009 13:46:33 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22937750</link>
<description><![CDATA[Dude111 posted : Cant you make ALL PORTS stealth with your firewall??<br><br>I even have port 113 stealthed!!<br><br>Good luck bud!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22937750</guid>
<pubDate>Fri, 28 Aug 2009 10:12:05 EDT</pubDate>
</item>

<item>
<title>Re: Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22929757</link>
<description><![CDATA[TearAbite posted : i dont think i would lose any sleep over it.   I would stress more over ensuring that my OS is secure.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22929757</guid>
<pubDate>Wed, 26 Aug 2009 21:08:53 EDT</pubDate>
</item>

<item>
<title>Port 0 and 1 Shows Closed not stealth Please helo</title>
<link>http://www.dslreports.com/forum/Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22929749</link>
<description><![CDATA[chascent posted : Is this a reason for concern, all ports show stealth except Port 0 and 1. How do I stealth these on my Dlink router????<br><br>Chrlie C]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Port-0-and-1-Shows-Closed-not-stealth-Please-helo-22929749</guid>
<pubDate>Wed, 26 Aug 2009 21:07:12 EDT</pubDate>
</item>

</channel>
</rss>

