<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Closed vs. Filtered in Security</title>
<link>http://www.dslreports.com/forum/r7615482</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 19:37:30 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 19:37:30 EDT</lastBuildDate>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7627418</link>
<description><![CDATA[<A HREF="/useremail/u/809112"><b>reaver221</b></A> : I could very well be wrong, but wouldn't 'stealth' help to defeat accurate OS detection?<br><br>For example, nmap supposedly needs to get responses from both closed and open ports to do a good job of detecting a target host's OS, because 'stealth' = less OS specific packets to fingerprint.<br><br>I didn't get a chance to read much of the thread that Randy linked to, so this could've already be talked about. :)<br><i>[text was edited by author 2003-08-08 19:30:44]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7627418</guid>
<pubDate>Fri, 08 Aug 2003 19:29:06 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7626563</link>
<description><![CDATA[<A HREF="/useremail/u/744768"><b>catahoula7</b></A> :  <BLOCKQUOTE><SMALL>said by  Reverend Ike <A HREF="/useremail/u/459195"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR><br><br>Stealth is like a phone with Caller ID. A telemarketing autodialer calls, the resident doesn't answer, the phone rings and rings. Closed is like an answering machine with an auto-response "There is nobody at home" which doesn't accept incoming messages. In either case, the autodialer just moves on. But when the autodialer starts a new cycle, it will call the same number again, just in case someone might answer next time.<br><br>On paper, it seems slightly more desirable to have your ports stealthed rather than closed. But in the real world, with zombie machines and lightning-fast port scanners, I don't think it makes any difference. Nobody is going to sit around and keep hammering one port just because it is "closed" rather than "stealthed", when there are millions of <B>open</B> ports waiting on millions of other machines ... :) <HR></BLOCKQUOTE><br><br>Excellent! A very clear analogy.<br><br>Thank you.<br><small>--<br>--Catahoula Hound Dawg</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7626563</guid>
<pubDate>Fri, 08 Aug 2003 17:55:53 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7625541</link>
<description><![CDATA[<A HREF="/useremail/u/203819"><b>R2</b></A> : Well said.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7625541</guid>
<pubDate>Fri, 08 Aug 2003 16:00:46 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7624659</link>
<description><![CDATA[<A HREF="/useremail/u/459195"><b>Reverend Ike</b></A> : <br>I think the critical question is whether the person ("hacker") sending the packets actually cares whether a port is "closed" or "stealth". IMHO, I doubt it. If a port is stealthed, does the hacker put it on a "don't bother" list and never try that port again? Of course not. He has no way of knowing that a stealthed port won't be an open port an hour or a day or a week from now. Same thing with a closed port. For the moment, all he cares about is "open" or "other". If it's open, he tries to break in, if it's other, he moves on to the next port or next IP address.<br><br>Stealth is like a phone with Caller ID. A telemarketing autodialer calls, the resident doesn't answer, the phone rings and rings. Closed is like an answering machine with an auto-response "There is nobody at home" which doesn't accept incoming messages. In either case, the autodialer just moves on. But when the autodialer starts a new cycle, it will call the same number again, just in case someone might answer next time.<br><br>On paper, it seems slightly more desirable to have your ports stealthed rather than closed. But in the real world, with zombie machines and lightning-fast port scanners, I don't think it makes any difference. Nobody is going to sit around and keep hammering one port just because it is "closed" rather than "stealthed", when there are millions of <B>open</B> ports waiting on millions of other machines ... :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7624659</guid>
<pubDate>Fri, 08 Aug 2003 14:21:45 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7622521</link>
<description><![CDATA[<A HREF="/useremail/u/203819"><b>R2</b></A> :  <BLOCKQUOTE><SMALL>said by  catahoula7 <A HREF="/useremail/u/744768"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>So the "closed" state would be the most idea(l) then. Or so it sounds, because the probing computer would have no evidence of a service there to attack.<br><br>It sounds as if "stealth" lets the hacker know there is a firewall there because the packet was simply dropped.<HR></BLOCKQUOTE>It depends on how you look at it...<br><br>I believe the term "stealth", was coined or at least put into THIS general use by GRC.  Previously, the term "stealth" refered to the TYPE of port scan being done.  Regardless, at this point in time we have to accept that many people are going to use the term "stealth" to mean "filtered" -- which simply means the packet was "dropped".  This means, the receiving computer sends NO acknowledgement back to the requesting computer.<br><br>If someone is probing your ports and every single probe is not returned, then your computer is relatively "invisible" -- meaning that the prober does not know <I>for sure</I> if your computer is on the Internet or not.  You could simply have your computer turned off or unplugged it -- the prober cannot easily tell.  You cannot assume with 100% certainty that a "stealth" response (i.e., no response) means the user has a firewall.<br>______________________________<br><br>An "ICMP-Host Unreachable" packet is not generated when a firewall "drops" or "filters" a packet -- as stated above.  <br><br>However, when I tried to probe non-existent IP addresses (e.g., 123.123.123.123 or 111.111.111.111) with 4 TCP/IP SYN packets, I also got NO RESPONSE -- the reqests "timed out".  I did NOT get back any ICMP-Host Unreachable packets -- I don't know why.  I just know that when I probed port 80 on those addresses with 4 TCP/IP SYN packets, I got no reponse at all.<br><br>If I probe port 80 at DSLR, I get an OPEN response (open = SYN/ACK) -- see above.  If I probe port 81 at DSLR, I get a CLOSED response (ACK/RST).  If I probe port 1234 at DSLR, I get back nothing -- a "filtered" or "stealth" response -- if you will.  I get the same response (NONE) when I probe port 1234 here that I do when I probe any port at the non-existant sites.<br><br>That being said, I then tried a simple ping of those addresses, and I found this:<br><SMALL><br>Pinging 123.123.123.123 with 32 bytes of data:<br><br>Request timed out.<br>Reply from 65.112.160.53: Destination host unreachable.<br>Request timed out.<br>Reply from 65.112.160.53: Destination host unreachable.<br><br>Ping statistics for 123.123.123.123:<br>    Packets: Sent = 4, Received = 2, Lost = 2 (50% loss),<br>Approximate round trip times in milli-seconds:<br>    Minimum = 0ms, Maximum =  0ms, Average =  0ms<br><br>C:\WINDOWS\Desktop>ping 111.111.111.111<br><br>Pinging 111.111.111.111 with 32 bytes of data:<br><br>Request timed out.<br>Reply from 65.123.254.57: Destination host unreachable.<br>Request timed out.<br>Request timed out.<br><br>Ping statistics for 111.111.111.111:<br>    Packets: Sent = 4, Received = 1, Lost = 3 (75% loss),<br>Approximate round trip times in milli-seconds:<br>    Minimum = 0ms, Maximum =  0ms, Average =  0ms<br></SMALL><br>Which -- I believe -- just so happens to prove MeDuZa's point!:)  Even though I got no response to a TCP/IP probe, at least SOME of the ICMP probes clearly come back Destination Host Unreachable.  But not all...<br><br>Therefore, perhaps with extensive probing one could figure out with some partial degree of certainty that the computer has a firewall.  BUT... given the eratic response of the ICMP packets, this seems a little challenging and makes it difficult to be absolutely certain....<br><i>[text was edited by author 2003-08-08 10:39:29]</i><br><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/7622521?c=403980&ret=L2ZvcnVtL3I3NjE1NDgyLnhtbA%3D%3D"><IMG TITLE="75231 bytes" BORDER=0 WIDTH=566 HEIGHT=651 SRC="/r0/download/403980~13f7012ee90393c63e6b3b8dfee16689/PPing.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7622521</guid>
<pubDate>Fri, 08 Aug 2003 10:35:32 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7617340</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> :  <BLOCKQUOTE><SMALL>said by  gwion <A HREF="/useremail/u/273056"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>The state  is  either "open", "filtered", or "unfiltered".  Open means that the target machine will accept connections  on  that  port.  Filtered  means  that a firewall, filter, or other network obstacle is covering the port  and preventing  nmap  from determining  whether  the  port is open.  Unfiltered means that the port is known by nmap to be closed and  no  firewall/filter  seems  to be interfering with nmap's attempts to determine this.  Unfiltered ports are the common case and  are  only shown when most of the scanned ports are in the filtered state.<br> <HR></BLOCKQUOTE>Precisely what  R2 <A HREF="/useremail/u/203819"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> stated, thanks  gwion <A HREF="/useremail/u/273056"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.<br><SMALL><br><i>[text was edited by author 2003-08-07 19:57:30]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7617340</guid>
<pubDate>Thu, 07 Aug 2003 19:47:09 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7617188</link>
<description><![CDATA[<A HREF="/useremail/u/273056"><b>gwion</b></A> : I think he may be using "filtered" as used as a term of art by nMap and nMap inspired port scanners, perhaps? An nMap scan might return something like:<br><br>Starting nmap V. 3.10ALPHA3 ( www.insecure.org/nmap )<br>Interesting ports on 195.98.xxx.xxx:<br>(The 1601 ports scanned but not shown below are in state: filtered)<br>Port State Service<br>21/tcp open ftp<br>22/tcp open ssh<br>113/tcp closed auth<br><br>From the nMap man page, &raquo;<A HREF="http://www.insecure.org/nmap/data/nmap_manpage.html" >www.insecure.org/nmap/data/nmap_manpage.html</A> :<br><br>The  result of running nmap is usually a list of interest&shy;<br>       ing ports on the machine(s) being scanned (if any).   Nmap<br>       always  gives  the  port's  "well  known" service name (if<br>       any), number, state, and protocol.  The  state  is  either<br>       "open",  "filtered", or "unfiltered".  Open means that the<br>       target machine will accept()  connections  on  that  port.<br>       Filtered  means  that a firewall, filter, or other network<br>       obstacle is covering the port  and  preventing  nmap  from<br>       determining  whether  the  port is open.  Unfiltered means<br>       that the port is known by nmap to be closed and  no  fire&shy;<br>       wall/filter  seems  to be interfering with nmap's attempts<br>       to determine this.  Unfiltered ports are the  common  case<br>       and  are  only shown when most of the scanned ports are in<br>       the filtered state.<br><small>--<br><I>I'm not good,<BR>I'm not nice,<BR>I'm just right.<BR>I'm the Witch.<BR>You're the world.</I></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7617188</guid>
<pubDate>Thu, 07 Aug 2003 19:30:32 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7617142</link>
<description><![CDATA[<A HREF="/useremail/u/744768"><b>catahoula7</b></A> :  <BLOCKQUOTE><SMALL>said by  Marilla <A HREF="/useremail/u/732377"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>"stealth" is mostly, from what I understand, a term used by online scanning utilities.. like the scanner here on this site. They report that the ports they check are in one of three states:<br>[..]<br><br>"Reject" and "Deny" are terms that the firewall itself uses as to what it does. I MIGHT have these backwards (I always get them backwards! hehe)...<br>[..]<br>so the confusion stems from two separate sets of terms, used in two different realms of discussion... from the point of view of the port scanner, or of the firewall. <HR></BLOCKQUOTE><br><br>I get them backwards too sometimes ! lol<br><br>So the "closed" state would be the most idea then. Or so it sounds, because the probing computer would have no evidence of a service there to attack.<br><br>It sounds as if "stealth" lets the hacker know there is a firewall there because the packet was simply dropped.<br><small>--<br>--Catahoula Hound Dawg</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7617142</guid>
<pubDate>Thu, 07 Aug 2003 19:24:45 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7616281</link>
<description><![CDATA[<A HREF="/useremail/u/825862"><b>MeDuZa</b></A> : The frequently used association of STEALTH with INVISIBLE is snake oil.<br>In case you wouldn't be there the nearest router located at your provider would respond with<br>"ICMP-Host unreachable"<br>No answer means that you are there and the requests have been dropped by a packet filter(FW)<br><br>REJECT means an active refuse of a connection attempt with a special ICMP message.<br>DENY means to throw away the connection attempts. The inquiring computer gets a timeout in this case.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7616281</guid>
<pubDate>Thu, 07 Aug 2003 17:52:18 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7615625</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : In the context of the thread title: "closed vs filtered" -- I think  R2 <A HREF="/useremail/u/203819"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> got it right:  <BLOCKQUOTE><SMALL>said by  R2 <A HREF="/useremail/u/203819"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>for TCP/IP ports:<br><br><B>Filtered = Stealth</B> = <I>no response at all</I> is sent back to the requesting site.<br><br><B>Closed</B> = a <I>specific</I> "port is closed" response is sent back to the requesting site. <HR></BLOCKQUOTE>I think the other interpretation is not consistent with what the thread author means in his thread title.  JMHO, HTH  ;-)<br><small>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7615625</guid>
<pubDate>Thu, 07 Aug 2003 16:41:11 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7615482</link>
<description><![CDATA[<A HREF="/useremail/u/732377"><b>Marilla</b></A> : "stealth" is mostly, from what I understand, a term used by online scanning utilities.. like the scanner here on this site. They report that the ports they check are in one of three states:<br><br>Open: Meaning a service is active and responding on that port.<br>Closed: Meaning communications are getting through to the host on the port in question, but that host has no daemons/services and is responding to that effect.<br>Stealth: Meaning the communication was simply dropped, and no response was sent at all.<br><br>"Reject" and "Deny" are terms that the firewall itself uses as to what it does. I MIGHT have these backwards (I always get them backwards! hehe)... but when a firewall "Rejects" a packet, that will result in a "Stealthed" result.. when a firewall "Deny", there may be a "Closed" response... As I said, I may have 'reject' and 'deny' backwards... but one simply sends the communication to the great packet bucket in the sky, but the other one sends a specific reply saying, "nothing to see here".<br><br>so the confusion stems from two separate sets of terms, used in two different realms of discussion... from the point of view of the port scanner, or of the firewall.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7615482</guid>
<pubDate>Thu, 07 Aug 2003 16:26:36 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7615409</link>
<description><![CDATA[<A HREF="/useremail/u/744768"><b>catahoula7</b></A> :  <BLOCKQUOTE><SMALL>said by  R2 <A HREF="/useremail/u/203819"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR> <BLOCKQUOTE><SMALL> <br><br><B>Filtered = Stealth</B> = <I>no response at all</I> is sent back to the requesting site.<br><br><B>Closed</B> = a <I>specific</I> "port is closed" response is sent back to the requesting site. <HR></BLOCKQUOTE><br><br>I thought "Reject" sent a response  And "DENY" just dropped the packet.<br><br>Where did "stealth" come from anyway? I thought there was just the "Drop" and "Reject" flags?<br><br> <br><small>--<br>--Catahoula Hound Dawg</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7615409</guid>
<pubDate>Thu, 07 Aug 2003 16:18:31 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7613724</link>
<description><![CDATA[<A HREF="/useremail/u/203819"><b>R2</b></A> :  <BLOCKQUOTE><SMALL>said by catahoula:</SMALL><HR>If i understand correctly, filtered and closed will give the same response to someone probing that port. Which is nothing. The packet will just silently be dropped and it will seem that there is no computer at the end.<HR></BLOCKQUOTE>Not exactly...  for TCP/IP ports:<br><br><B>Filtered = Stealth</B> = <I>no response at all</I> is sent back to the requesting site.<br><br><B>Closed</B> = a <I>specific</I> "port is closed" response is sent back to the requesting site.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7613724</guid>
<pubDate>Thu, 07 Aug 2003 13:19:40 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7611588</link>
<description><![CDATA[<A HREF="/useremail/u/744768"><b>catahoula7</b></A> :  <BLOCKQUOTE><SMALL>said by  Maven <A HREF="/useremail/u/599546"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Forgive me if this has been answered before, but I search Yahoo and the security FAQ yet came out empty. What is the difference between closed and filtered ports? If a computer has all it's ports closed, why would it not be fine? <HR></BLOCKQUOTE><br><br>Yes, that should be fine.<br>If i understand correctly, filtered and closed will give the same response to someone probing that port. Which is nothing. The packet will just silently be dropped and it will seem that there is no computer at the end.<br><br>OTOH, if the firewall is set to "deny" it drops the packets and notifies the probing host that the packet was rejected.<br>Which lets the probing computer know there is a machine at the other end.<br><small>--<br>--Catahoula Hound Dawg</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7611588</guid>
<pubDate>Thu, 07 Aug 2003 07:29:20 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7611170</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> :  <BLOCKQUOTE><SMALL>said by  Maven <A HREF="/useremail/u/599546"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>In my case, since the command netstat -an reports nothing unless running an internet application, I assume that running a firewall would be redundant. I am on WinME with NetBios disabled and not running file sharing. <HR></BLOCKQUOTE>Maybe sometimes little "redundant" so far as <B>inbound</B> traffic control; but not so far as <B>outbound</B> control.  Without a firewall, you have no outbound control, over rogue programs or apps that might try to connect out to the Net.  You also have no logging of traffic in/out of your box.  This is why I usually recommend a software firewall, even for people who have a NAT router; since the router takes care of <B>inbound</B> traffic but has no effective <B>outbound</B> control.  I too have a tight system with NetBEUI substituted for local networking, file sharing and NetBIOS uncoupled {unbound} from TCP/IP, etc. -- but I still use ZA on all boxes in my home network.  HTH ;-)<br><small>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7611170</guid>
<pubDate>Thu, 07 Aug 2003 03:41:59 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7611115</link>
<description><![CDATA[<A HREF="/useremail/u/599546"><b>Maven</b></A> : Thanks for the replies.<br><br>Wow, that's quite the discussion  Randy Bell <A HREF="/useremail/u/590730"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>. I've only read the first 2 pages, but I've picked up the gist of it so far - Stealth is overrated. It reminds me of the recent thread called "Uh Oh... You're not going to like this!" (&raquo;<A HREF="/forum/remark,7594744~root=security,1~mode=flat">Uh Oh... You're not going to like this!</A> , where there is an interesting discussion on whether firewalls are useful or not.<br><br>In my case, since the command netstat -an reports nothing unless running an internet application, I assume that running a firewall would be redundant. I am on WinME with NetBios disabled and not running file sharing.<br><i>[text was edited by author 2003-08-07 03:27:57]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7611115</guid>
<pubDate>Thu, 07 Aug 2003 03:23:22 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7610925</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : The classic discussion at DSLR was done in this old thread:<br><br>Closed vs Stealthed Ports<br>&raquo;<A HREF="/forum/remark,3490473~root=security,1~mode=flat">Closed vs Stealthed Ports</A><br><br>but it is quite long, I warn you .. yet very informative and interesting.<br><small>--<br><I>"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)</I></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7610925</guid>
<pubDate>Thu, 07 Aug 2003 02:26:06 EDT</pubDate>
</item>

<item>
<title>Re: Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7610877</link>
<description><![CDATA[<A HREF="/useremail/u/732377"><b>Marilla</b></A> : Someone may correct me on specifics... as nit-picky as I can be, I'm not always that great on exact wording... that said:<br><br>As far as I understand it, 'Closed' and 'Filtered' aren't really directly related... <br><br>Closed means that no daemon/service is configured to respond on the port in question on a specific host.<br><br>Filtered means that there is a firewall somewhere which is 'intercepting' and dropping communications for a port. Actually, you don't so much filter a PORT as you filter datagrams based on whatever the rules are... and it's entirely possible that the 'rules' can be "drop all packets for this port" or "drop all packets EXCEPT those for this port"<br><br>The reason I say they aren't neccesarily directly related is this: It's entirely possible for a port to be OPEN, yet filtered. In fact, that's one of the greatest reasons to have a firewall in the first place: To enable a service (such as file sharing) to be available on your private network, but to have connections from outside to that service 'filtered' such that they do not get through.<br><br>Or.. umm.. something like that!<br><br>So, to answer your last question: If ALL of the ports are truly closed, then it would seem there isn't really a need for them to be filtered, too... but.. there's justa  little more, because I mentioned a THIRD possibility above: Dropped.<br><br>When a port is 'closed', say port 80, and I try to connect to a computer on that port, the computer in question usually sends back an instant reply saying, "Hey, I don't have any service running on that port!" That's the normal behavior on a 'closed' port.<br><br>When communications to that port are "filtered" or "dropped", though... that "there's nothing here" response never gets sent. This is usually what some online tests mean when they say a port is 'stealthed', and it is a little better than simply being 'closed', because it forces a port scan to wait for a timeout before it can declare the port responding or not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7610877</guid>
<pubDate>Thu, 07 Aug 2003 02:17:20 EDT</pubDate>
</item>

<item>
<title>Closed vs. Filtered</title>
<link>http://www.dslreports.com/forum/remark,7610828</link>
<description><![CDATA[<A HREF="/useremail/u/599546"><b>Maven</b></A> : Forgive me if this has been answered before, but I search Yahoo and the security FAQ yet came out empty. What is the difference between closed and filtered ports? If a computer has all it's ports closed, why would it not be fine?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7610828</guid>
<pubDate>Thu, 07 Aug 2003 02:06:51 EDT</pubDate>
</item>

</channel>
</rss>
