hescominsoon
join:2003-02-18 Brunswick, MD | Re: Rolling my own so far this is easy to defeat..do not let NAT decrement the counter..and use a firewall(either in the NAT box itself or the clients) that block OS fingerprinting..problem solved. -- God Blesshttp://www.faithwalk.org | |
|
  Kylemaul Lovin' My Firefox 1.5.x Premium join:2001-03-30 North Port, FL clubs:
·Verizon FIOS
| Re: Rolling my own Errrrrrr....could you dumb your post down a little for us poor novices? How do you determine if your NAT router has the capability to disable decrementing a counter? And what is decrementing and what is 'the counter'? -- 'The tighter the RIAA squeezes their fingers, the more stars and systems will slip through their fingers.' | |
|
 |  DonLibes Premium,ExMod 2001 join:2003-01-19 | Re: Rolling my own I think the reference to decrementing the counter was a reference to TTL. But that's not how Bellovin's technique worked. | |
|
 |  |
 |  |   succintly put
@207.99.x.x
| Re: Rolling my own Iptables supports 'packet mangling' as just one of it's many functions. Packet mangling changes the packet headers.
You can get a lot more advice and help in the 'All Things Unix' forum. I -may- get a friend to write and post a 'how-to' in ATU when I'm done. 'nuff said. | |
|
 |  |  |   amenite The Soylent - It's People Premium join:2002-11-21 Ridgewood, NJ clubs:
·Verizon Online DSL
| Re: Rolling my own said by succintly put: ... You can get a lot more advice and help in the 'All Things Unix' forum. I -may- get a friend to write and post a 'how-to' in ATU when I'm done. 'nuff said.
That would be excellent, the topic is a little obscure to many of us. -- Time is an abstract concept invented by carbon based life forms to monitor their constant decay.-Thunderclese | |
|
 |
 |  |
 |  |   AthlGrond Premium,MVM join:2002-04-25 Aurora, CO
·Comcast
| Re: Rolling my own said by amenite : The ID in question is the IP id string assigned to each packet by the OS, not the IP address of the NAT device.
Are the IPid's not assigned by the NAT device? Seems like they would have to be. (so the NAT device could send the packets to the correct IP in the LAN) | |
|
 |  |  |  |
 |  |  |  |   AthlGrond Premium,MVM join:2002-04-25 Aurora, CO | Re: Rolling my own Thanks, I reread it and much clearer now. You are correct. | |
|
 |
|
 |