"udp non stealthed" na potscan-test bij sygate en pcflank

Pagina: 1
Acties:

  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Ik heb een vigor 2200 E router (firmware 2.2) en heb een vraag over de ingebouwde standaard firewall:

Hoe kan ik op eenvoudige wijze ervoor zorgen dat de udp-portscan ook op "stealth" komt, bij een portscantest en dan wel bij "sygate" en "pcflank-site"?

Bij steve gibson's "grc.com" staat alles op stealth, maar ik hecht iets meer waarde aan de uitvoerige test van beide genoemde : pcflank en sygate

Is het wel nodig, om udp ook af te schermen?
Ik game niet of nooit via internet..

Misschien kunnen enkele vigor2200E-users me op weg helpen... _/-\o_

  • Yalopa
  • Registratie: Maart 2002
  • Niet online

Yalopa

Less is more!

over welke poort(en) praten we?

You don't need eyes to see, you need vision


  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Bij de udp-portscan bij sygate kwam dit uit de bus en bij de stealth-scan bij pcflank, kwam dit eruit:


Sygate UDP-Scan:

FTP DATA 20 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
FTP 21 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
SSH 22 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
TELNET 23 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
SMTP 25 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
DNS 53 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
DCC 59 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
DHCP SERVER 67 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
FINGER 79 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
WEB 80 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
POP3 110 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
SUNRPC 111 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
IDENT 113 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Location Service 135 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
NetBIOS-NS 137 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
NetBIOS-DGM 138 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
NetBIOS 139 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
HTTPS 443 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Server Message Block 445 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
SOCKS PROXY 1080 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
UPnP 1900 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
WEB PROXY 8080 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Results from UDP scan of commonly used trojans at IP address: ……………
Service Ports Status Possible Trojan
Trojan 6776 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Trojan 12345 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Trojan 20034 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Trojan 31337 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Trojan 54320 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.
Trojan 54321 CLOSED This port has responded to our probes. This means that you are not running any application on this port, but it is still possible for someone to crash your computer through known TCP/IP stack vulnerabilities.


PCFLANK STEALTH SCAN:


We have sent following packets to TCP:1 port of your machine:
• TCP ping packet
• TCP NULL packet
• TCP FIN packet
• TCP XMAS packet
• UDP packet
Here is the description of possible results on each sent packet:
"Stealthed" - Means that your system (firewall) has successfuly passed the test by not responding to the packet we have sent to it.
"Non-stealthed" - Means that your system (firewall) responded to the packet we have sent to it. What is more important, is that it also means that your computer is visible to others on the Internet that can be potentially dangerous.
Packet' type
Status
TCP "ping" stealthed
TCP NULL stealthed
TCP FIN stealthed
TCP XMAS stealthed
UDP non-stealthed


Recommendation:

Install personal firewall software. If you have already installed and are using a firewall, check if it is set to make all the ports of your computer invisible (stealthed). If it is, then get new firewall software and redo this test.

  • Cpt.Morgan
  • Registratie: Februari 2001
  • Laatst online: 23-11-2025
Waarom is het zo belangrijk dat ze 'stealthed' zijn? Zeker als dit voor thuisgebruik is. zou ik me niet druk maken over UDP packets....

  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Ik weet niet veel van deze materie, maar heb wel geprobeerd er meer over te vinden.
Over "udp-non stealth" niet veel gevonden in de search op GOT.

Udp wordt volgens mij ook gebruikt bij o.a. online-gaming. Ben jij ook een vigor-gebruiker?

Ik ging er van uit dat ik misschien m'n firewall beter moest "tunen", misschien ben ik iets vergeten..

Mochter er nog vigor 2200e users zijn, reageer dan a.u.b.

  • Miki
  • Registratie: November 2001
  • Laatst online: 23:01
Ik heb dus hier precies hetzelfde met mijn vigor2200E router, echter vraag ik me af of ik me hierom zorgen moet maken. Ben ik zo interesant om gehackt te worden :?

Heb een tijdje zonealarm pro en mcafee firewall gedraaid maar allebij eraf gedonderd. Ik zie het nut er niet van in, alleen maar ergenissen. Meestal is je firewall dan "te goed" waardoor surfen niet meer leuk word (van wege "missing" dit en dat en weet ik veel) en zelfs trager word door het constante gefilter.

  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Hoi "Miki",

Zonde dat je Zone Alarm eraf gooit, want die houdt voor me bij welk programma "stiekem" eruit wil (denk evt. aan trojans etc..), het klopt dat de ZA "in functie" wegvalt als de router-firewall de zaak overneemt.

Ik maak weleens contact met de zaak van m'n dochter (via internet), daarom blijf ik toch voorzichtig...

  • Miki
  • Registratie: November 2001
  • Laatst online: 23:01
apacer schreef op 28 december 2002 @ 12:24:
Hoi "Miki",

Zonde dat je Zone Alarm eraf gooit, want die houdt voor me bij welk programma "stiekem" eruit wil (denk evt. aan trojans etc..), het klopt dat de ZA "in functie" wegvalt als de router-firewall de zaak overneemt.

Ik maak weleens contact met de zaak van m'n dochter (via internet), daarom blijf ik toch voorzichtig...
Hmm mee eens, maar met een goede virus scanner heb je geen last van trojans en virussen. De meeste virussen/trojans ontvang je meestal via mail of van duistere programmaatjes die iemand zelf uitprobeerd. Virus zomaar krijgen bestaat niet een virus/trojans moet altijd geactiveerd worden. Neemt niet weg dat men steeds creatiever word om iemand een virus/trojans te laten activeren. "Kournikova virus" en het "I love you virus" zijn hele goede voorbeelden daarvan.

Als je de vigor firewall niet vertrouwd kun je daarnaast zonealarm gebruiken of een andere goede firewall (tiny, kerio, sygate. mcafee, norton). Deze zal dan het overige voor je filteren. Het is dan wel een beetje dubbel op maar dan zit je naar alle waarschijnlijkheid potje dicht.

[ Voor 4% gewijzigd door Miki op 28-12-2002 12:57 ]


  • Yalopa
  • Registratie: Maart 2002
  • Niet online

Yalopa

Less is more!

Alles is closed voor zover ik kan zien, dat houd in dat een connectie van buitenaf het anwoord krijgt dat ie er niet in kan/mag. Stealthed wil zeggen dat ie zelf dat antwoord niet krijgt, maw het lijkt alsof de host niet bestaat.

Als toch alles closed is zou ik me weinig zorgen maken, er komt toch niemand in. Als zonalarm voor jou een extra gerustelling is dan houd je dat toch gewoon? het zal niet ik de weg lopen.

You don't need eyes to see, you need vision


  • Redje
  • Registratie: Juli 2000
  • Laatst online: 18-08 21:30
Ook met Vigor 2200E:

Packet' type Status
TCP "ping" stealthed
TCP NULL stealthed
TCP FIN stealthed
TCP XMAS stealthed
UDP stealthed

Recommendation:

Your computer is invisible to the others on the Internet! :)


Lijkt me een firmware prob, ik gebruik 2.0a omdat bij de nieuwere de IN filter niet werkt/uit staat.

Verwijderd

Ik neem aan dat port-forwarding mogelijk is met dat apparaat.
Zoals met mijn freesco bak heb ik alle(bekende) poorten geforward naar een niet bestaand ip adres op mijn netwerk en dan krijg ik als resultaat "stealthed" (dit houdt het log ook mooi schoon)

  • Fish
  • Registratie: Juli 2002
  • Niet online

Fish

How much is the fish

ik heb dan wel geen vigor maar een ding weet ik wel, en mis ik in dit verhaal
Je kan een conectie droppen of denyen

Met "deny" weiger je dus een verbinding.. je geeft dus antwoord dus de pc aan de andere kant weet dus wel dat er "iets" is.

Met "drop" doe je er gewoon helemaal niks mee dus ook niet weigeren
dit resulteerd dus in stealth.

electromasters antwoord is ook goed maar vind ik persoon lijk wat "slordig" als het ook op de andere manier kan

het zou me niet verbazen dat deze optie er op zat. vigor heeft teslotte wel een goeie reputatie

Iperf


  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Redje schreef op 28 December 2002 @ 14:27:
Ook met Vigor 2200E:

Packet' type Status
TCP "ping" stealthed
TCP NULL stealthed
TCP FIN stealthed
TCP XMAS stealthed
UDP stealthed

Recommendation:

Your computer is invisible to the others on the Internet! :)


Lijkt me een firmware prob, ik gebruik 2.0a omdat bij de nieuwere de IN filter niet werkt/uit staat.
Ik zal even naar de andere voor- en nadelen van firmware 2.0a kijken en misschien de 2.0a versie uitproberen.

Iedereen bedankt voor het meedenken..

Voor de rest is deze router echt een prachtig ding.

Beste wensen voor 2003!

  • nero355
  • Registratie: Februari 2002
  • Laatst online: 10-07 17:18

nero355

ph34r my [WCG] Cows :P

Ik heb WinRoute als NAT Router en heb ook gewoon en op die pc een norton security versie geinstalled en op alle andere pc's ;)

Is wel handig als een proggie die windows ingebouwd is MSN wil contacten tegen jouw zin in of je toch per ongeluk spyware heb geinstalled :)

|| Stem op mooiere Topic Search linkjes! :) " || Pi-Hole : Geen advertenties meer voor je hele netwerk! >:) ||


  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Met de versie 2.3 voor de vigor 2200E is de zaak nu eindelijk potdicht!
Na firmware upgrade, alles naar fabrieksmode gebracht en alles netjes ingevuld via webmenu (zoals isp gegevens, inlognaam etc, de router rebooten, testen gedraaid op sygate en pcflank en.... alles stealth, het is dus wel mogelijk.

Ik heb niets aan de data en call filter gedaan!

Even nog kijken nu of 2.3 stabiel is..

  • Miki
  • Registratie: November 2001
  • Laatst online: 23:01
apacer schreef op 11 January 2003 @ 12:30:
Met de versie 2.3 voor de vigor 2200E is de zaak nu eindelijk potdicht!
Na firmware upgrade, alles naar fabrieksmode gebracht en alles netjes ingevuld via webmenu (zoals isp gegevens, inlognaam etc, de router rebooten, testen gedraaid op sygate en pcflank en.... alles stealth, het is dus wel mogelijk.

Ik heb niets aan de data en call filter gedaan!

Even nog kijken nu of 2.3 stabiel is..
En waar kan ik hem downloaden, vanochtend nog gekeken maar alleen versie 2.2.4 beta was er.

  • Miki
  • Registratie: November 2001
  • Laatst online: 23:01
Miki schreef op 11 januari 2003 @ 13:36:
[...]


En waar kan ik hem downloaden, vanochtend nog gekeken maar alleen versie 2.2.4 beta was er.
Schop*

Hoe kom jij in godsnaam aan versie 2.3 voor de vigor 2200 E router, ik kan op verschillende draytek sites alleen de laatste beta vinden :(

  • apacer
  • Registratie: December 2002
  • Laatst online: 01-02 19:54
Sorry ik heb een type-fout gemaakt, het is versie 2.2.3 en jij je maar rot zoeken!
Excuse me sir! 8)7
Pagina: 1