  aefstoggaflm Open Source Fan Premium join:2002-03-04 Bethlehem, PA
·Verizon Online DSL
| stealth issue (fake them)
I saw the webpage at »www.hansenonline.net/Networking/stealth.html
quote: The lack of this "host unreachable" message is a clear indication that something is there and it's dropping the packets rather than replying to them.
and that has got me thinking..
Is there any way to send "host unreachable" message back to them, even when my computer is turned on - To fake them into thinking that my computer is really off (or does not exist)..
..When using Software firewall and or using a router?
Please and thank you.  -- Please use the "yellow (IM) envelope" to contact me and please leave the URL intact. |
|
  nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T Midwest
| I am not convinced that the analysis is correct.
If I attempt to ping another host on the same subnet, and that host is down, then the ping fails. On linux I will see "Host Unreachable". But if I am using solaris, I will see "connection timed out". I don't think I have ever seen "host unreachable" in these circumstances, except when running linux. The cisco routers at work do not give "host unreachable" when the host (on a lan connected to that router) is down. -- AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1 |
|
 kpatz MY HEAD A SPLODE Premium join:2003-06-13 Manchester, NH
| It depends on the inbound gateway (router) in use at the destination host. Some may return the ICMP unreachable message if a host doesn't respond to ARP requests (meaning it's turned off), and a "stealthed" machine behind the same router would not cause the unreachable message, because the machine would reply to ARP, but drop the TCP/UDP/ICMP packets at the firewall. But many routers don't send the unreachable message for ARP non-replies, so stealth does "work" in this case. -- The "duh" is the basic unit of measurement of human stupidity. While one may try to measure stupidity in megaduhs(10^6) or gigaduhs(10^9), larger units such as exaduhs(10^18) or yottaduhs(10^24) are more appropriate for measuring on a global level. |
|