[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Fwd: packet filter fingerprinting(open but closed, closed but filtered)
On Mon, Apr 01, 2002 at 09:05:12PM +0200, Black Berry wrote:
> >recently playing with raw sockets and PF (OpenBSD 3.0) i noticed
> >that when you have return-rst rule for some tcp packet, ttl field
> >in ip header of rst packet, that is sent by PF, equals 128, while
> >default ttl for OpenBSD 3.0 is 64, so we can actually see what
> >tcp ports are blocked by pf and which are open, but closed(nothing
> >on them).
this behaviour has already been changed.
--
http://2suck.net/hhwl.html
Unix is very simple, but it takes a genius to understand the simplicity.
(Dennis Ritchie)