in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Stealth Mode

Last post 06-16-2007 6:58 AM by serv. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 06-06-2007 7:31 PM

    Stealth Mode

    I've refered to KB000549 and I'm still rather confused? What exactly does stealth mode do? Does it drop all incoming unsolicited packets TCP and UDP packets? What about ICMP?


     

  • 06-06-2007 10:09 PM In reply to

    • cimes
    • Top 10 Contributor
    • Joined on 06-05-2007
    • Posts 87

    Re: Stealth Mode

    "Stealth the System" is probably not well documented; however, its intentions are to minimize the information that the host sends out largely from the scanning of closed TCP and UDP ports. Specifically the option will:

    1) Drop TCP RST packets sent as a result of scanning closed TCP ports
    2) Drop ICMP port unreachable sent as a result of scanning closed UDP ports

    Receiving such packets is a common method used by discovery scanners (nmap or even our own Retina Vulnerability Assessment scanner) to identify a host as live. Admins may make an effort to disable many of the ICMP types and even many of the ports at least inbound; however, the simple fact of knowing that a port is closed implies that a host exists. By dropping these packets that are part of the protocol we effectively prevent this method of host discovery. Of course, open ports are unaffected and finding an open port also suggests a host exists. It is simply a means to limit the amount of "discriminating" traffic originating from a Blink protected asset.

    Hope this helps.

    Christopher I. (eEye)
  • 06-07-2007 8:05 AM In reply to

    Re: Stealth Mode

    Is it possible to configure the system firewall to drop all incoming unsolicited TCP UDP and ICMP packets by adding such a rule with the lowest priority? How will this interact with the stateful application firewall?
  • 06-16-2007 6:58 AM In reply to

    • serv
    • Top 25 Contributor
    • Joined on 06-14-2007
    • European Union
    • Posts 41

    Re: Stealth Mode

    You can make a test to see if you need to change something on your System.

    http://www.grc.com

    And then select one by one

    ShieldsUP! (Textlink)

    Proceed (Buttom)

    and then select wich Ports shall be tested (Buttom)

    Example: "Common Ports" or "All Service Ports"

    Regards
    Serv B.

Page 1 of 1 (4 items)
© 1995 - 2009 eEye Incorporated