Re: failed shields up test



Paul J Gans wrote:
Nikos Chantziaras <realnc@xxxxxxxx> wrote:

[...] For a recent Linux grc.com has nothing relevant to offer. Their "results" are simply meant to make you feel good but are irrelevant. Responding to pings is normal and there's no point in not responding to them. It can also cause problems. [...]

I think this is a matter of philosophy. I have another view,
which, you understand, does not mean that yours is wrong.

My belief is that thousands of guys trying to break into machines
do not waste their time on machines that are powered down. They
are *VERY* hard to break into.

So, my theory is, don't let them know you are there.
[...]

I'm not sure what the common behavior of ISPs is these days. Normally, when you ping a machine that isn't there, you get a reply *from the ISP* in form of an ICMP packet that says "the IP you just pinged isn't there" (disconnected, powered down, whatever). If the IP *is* there, but is "stealthed" (as Gibson puts it) and doesn't reply to pings, the pinger doesn't get the "is not there" ICMP. Therefore, the "attacker" knows you're there. So not replying to pings is like hiding behind your finger.

If the ISP does not send the ICMP packet in question, then "stealth" could be useful to avoid port scans and SSH login attempts.
.



Relevant Pages

  • Re: ICMP (Ping)
    ... >> scanning your server unless it responds to pings, ... then run a port scan against those ... running the vuln scan. ... Again, all I can say is that if you are responding to pings, then this ...
    (Security-Basics)
  • Re: Vista Firewall
    ... I have a "Sky Wireless Router". ... "Bruce Chambers" wrote: ... may be what is responding the the pings, ...
    (microsoft.public.windows.vista.security)
  • Re: What is my IP address?
    ... >is still responding to 'pings' and so fails the Shields Up test. ...
    (uk.telecom.broadband)
  • Re: How do I stop my PC from returning a "Ping"?
    ... Are you using a router or are you directly plugged to the cable modem? ... ZoneAlarm Pro, in its default configuration, does block replies to "pings" ... Now according to GRC's ShieldsUP, the only flaw in my> Windows XP Home system is that it returns anonymous pings:> ... > FWIW, I do have ZoneAlarm Pro, but have not fund any parameters I can> set to prevent my system from responding to these pings! ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Telnet: route to host
    ... >out why we couldn't reach anything on the internet - pings failed ... Or switch to an ISP that knows and understands networking. ... I see regular attacks on my machine, ... As to adding IPs to your filters you may find that your filters get ...
    (comp.unix.sco.misc)