 | reply to CrazyM
Re: UDP Port scans and you I do see a difference in behavior and it looks like the Linksys settings affect it. Dummy DMZ on, the UDP probes go the the dummy DMZ IP. DMZ off, SPI on, the UDP probes go to the WAN IP. DMZ off, SPI off, the Sygate Scan never finishes. I am wondering why. I assume that the SPI on never allows the UDP packets pass into the LAN but somehow the WAN IP is responding in a way that makes Sygate think that the port is there (but closed). Curious.
If I have both SPI and DMZ on the behavior seems to be the same as if just SPI was on. --
What can possibly go wrong? |
|
 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| said by Komputerguy:
If I have both SPI and DMZ on the behavior seems to be the same as if just SPI was on.
This would be as expected since SPI enabled, disables DMZ in the current firmware versions.
---- I've been using the DMZ trick for months now and never remember experiencing a lock-up. Interesting. ----
You would need to have enough unique traffic (different ports, source IP's etc) all happening within some time from to overflow the table before you saw this. I don't think I would recommend testing this as the table overflow could cause your linky some harm.
I'm under the impression that we are going to see some really really good and detailed posts (start the drum roll please) from the Linksys tech's concerning SPI and Port Triggering so hopefully these will help explain some of the differences you see between SPI on, and SPI off with the DMZ disabled.
So take it away Linksys techie guys Blake [text was edited by author 2001-06-22 23:45:20] |
|
 DeeCPremium join:2000-09-01 the world kudos:1 | Blake, I don't use DMZ, and left SPI at default, which I believe is "disabled" setting. Question, #1 What is the message the Linky gives to TCP or UDP scans? (Again, talking about "unsolicited traffic requests, of course)....
Thanks.....trying to figure out what the heck you guys are all saying ))) Q #2 Still don't know what the purpose of SPI is? But did read up on DMZ port, which seems dangerous to enable......
FYI: I had a friend scan me while on IRC.....and he said the Linky gave him some _SO_ERROR message back when he tried to get in (behind it), so then he tried to trick the Linky with "stealth" packets? (don't ask me, he was just telling me what he is doing next, lol), and that didn't work..... He was able to see, however, that I had open ports (should, on IRC, after all), but the Linky said something like, "ports open, but not available to public"...... Q #3 Sound right?
thanks in advance! This is some lesson! Linksys 101!!!!
Dee |
|
 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| 1. To a TCP scan the Linky returns nothing (you can stealth a TCP port, ie returning nothing). 2. The Linksys techies have promised a posting concerning SPI so I will leave it to them. It meant to validate which side of the Router traffic its found own, with the direction it claims to be traveling. 3. Was he connected to you (IRC) during the scan in which case he might have scanned the port you were already using for IRC? Stealth packets make no difference to the Linky. And again what were the ports he was claiming were open (UDP for example, as that was the reason for the original post).
Blake |
|
 DeeCPremium join:2000-09-01 the world kudos:1
| Here is our conversation (excuse the "very casual" jargon), with our IRC nicks taken out , of course Notice the PORT names he got from the Linky?? What is that about?
***IRC scan by friend (very good scriptor)**************
me: can you scan me for trojans? him: sure me: I scanned myself, and was clean him: well me: but when this damn program joined warez-central him: that doesnt mean you are him: let me nmap you me: someone said I tried to send them something him: ah him: thats not good me: yes, but it is a trick me: like yesterday, so that you go download their program me: from some no name site me: with no description me: that I believe is a trojan him: you g ot a firewall u p? me: yes me: hardware firewall me: spammers have new trick me: they tell people they are infected, and need to get clean him: nothings getting past your firewall him: damn me: then ppl go download me: some cleaner program me: from some unknown site me: and put trojan ON their PC! him: im trying to trick your firewall him: lol him: damn him: thats not good me: hey me: firewall working good? him: huh him: LOL me: I scanned my system with this him: yes him: so far him: I'm trying to make it think something e lse him: hold on me: »www.agnitum.com/products/tauscan/ me: the guys on DSLR said to use that me: it is true trojan scanning program me: took 1hr me: took 30 minutes him: its sending me a SO_ERROR him: for my little trick :/ him: hmmm me: but scanned entire PC, I was clean him: good me: I think spammers trying to trick me me: into downloading their trojan me: hey, what you doing now? me: my modem blinking? him: im trying to trick your firewall him: so I can run a scan him: im sending stealth packets to get through him: it might work him: hold on him: it wont hurt you him: im just seeing if i can do it  me: don't send me anything bad me: you packeting? him: i wont him: no him: no no him: i wouldnt do that to ya him: damnit the scan is bailing him: you got a good firewall me: (you said) its sending me a SO_ERROR him: hehe me: that is good right? him: yeah him: its good me: ok him: i tried tricking it him: thinking it was coming from localhost me: ok, that's good me: I feel better now him: and it gave an error him: it usually works him: woops him: i g ot through him: somewhat :/ him: your running an ftp arent you me: no me: serv-u is down him: but people cant connect him: heh him: hrm me: that is because I do have ports open me: but the firewall won't let in him: it shows the port open but closed from the public me: if serv-u closed me: yah me: lol me: I told router to allow "few" ports open him: rmonitor_secure him: whas that me: but only if I allow (serv-u or dcc) him: hacl him: mmcc him: cfengine him: weird me: what? the program? him: pcduo him: lol him: you got weird stuff open him: but your firewall makes you safe me: what is that stuff? him: just ports me: uh, maybe port names? me: linky maybe did that? me: obviously, some ports open me: to be on IRC ) him: well him: port names him: yeah me: kew me: kewl me: congrats on your new software! him: lol him: huh me: the new release him: ohh me: new release/update him: thanks =] me: ;p me: so, whats up? him: nothing much him: tryin to get my page up me: heh  him: hehe me: this is the trojan scan program I was told to use, might want to keep the link me: »www.agnitum.com/products/tauscan/ him: alright him: thanks me: k me: aight [text was edited by author 2001-06-24 10:36:08] |
|
 Bill_MIBill In MichiganPremium,MVM join:2001-01-03 Royal Oak, MI kudos:1 Reviews:
·Comcast
·WOW Internet and..
| Gee, can I bet what DCC ports you have forwarded? 
hacl-hb 5300/tcp # HA cluster heartbeat hacl-hb 5300/udp # HA cluster heartbeat hacl-gs 5301/tcp # HA cluster general services hacl-gs 5301/udp # HA cluster general services hacl-cfg 5302/tcp # HA cluster configuration hacl-cfg 5302/udp # HA cluster configuration hacl-probe 5303/tcp # HA cluster probing hacl-probe 5303/udp # HA cluster probing hacl-local 5304/tcp # HA Cluster Commands hacl-local 5304/udp hacl-test 5305/tcp # HA Cluster Test hacl-test 5305/udp cfengine 5308/tcp CFengine cfengine 5308/udp CFengine mmcc 5050/tcp multimedia conference control tool mmcc 5050/udp multimedia conference control tool |
|
 DeeCPremium join:2000-09-01 the world kudos:1 | Does this mean they were all detectable due to being on IRC or because they are forwarded on Linky? Second, are those names (hacl, cfengine, etc) assigned to the port by Linky? or mIRC?
English please? I left my WonderWoman Decoder Ring at home today 
Dee |
|
 Bill_MIBill In MichiganPremium,MVM join:2001-01-03 Royal Oak, MI kudos:1 Reviews:
·Comcast
·WOW Internet and..
| said by deecadams: Does this mean they were all detectable due to being on IRC or because they are forwarded on Linky?
They are in the range forwarded I assume? Let's see if I can simplify what I think is happening...
When you forward ports it takes the response to those ports away from the LinkSys and puts the burden where ever you forward them too. If it's a Windows PC... well... I've seen so many variations that depends on whether applications were previously listening to these ports, what updates are installed... a mess!
In other words, I would guess your Windows PC wasn't "stealth" on these ports - for some reason.
said by deecadams: Second, are those names (hacl, cfengine, etc) assigned to the port by Linky? or mIRC?
I got them from a big list I see is dated 1999 posted in a security newsgroup - it's been the best I've found but I'm due for an update, myself. Your script-fancy friend must simply have a similar list in his tools.
Did I help or hurt?  |
|
|
|
 DeeCPremium join:2000-09-01 the world kudos:1 | Bill...yes, kind of 
Yes, I have a "particular range" forwarded for DCC receives/sends on IRC I assume that is why they were exposed, but the Linky still told my scanner they were, "open, but not available to the public", which was fine with me 
Second, I don't know how he knew their names, but I"m sure he has all those special hacker/scriptor tools that many guys do on IRC 
thanks,
Dee |
|
 Bill_MIBill In MichiganPremium,MVM join:2001-01-03 Royal Oak, MI kudos:1 Reviews:
·Comcast
·WOW Internet and..
| Gee, Dee. If I exposed something you don't want public I'll be happy to edit mine if you'll edit yours (oh my... it's that picture....) 
Your hacker friend has a tool that only finds a port by number... he scans them all and finds, say, a "closed" reply on port 5300. His tools has some list that tells him:
hacl-hb 5300/tcp # HA cluster heartbeat
Someone, somewhere in the world (I bet this one is Cisco) used port 5300 to monitor the heartbeat of a High-Availability Cluster and labeled it "hacl-hb". It means nothing to your computer, you just used the same port # for something else - with me?
Bill |
|
 DeeCPremium join:2000-09-01 the world kudos:1 | Yup , thanks. ...And now you are under hypnosis of my avatar, "Send deecadams all your money , now....all of it, sell your house".....
"(oh my... it's that picture....)------really funny 
Dee |
|