Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752251AbbGLXO1 (ORCPT ); Sun, 12 Jul 2015 19:14:27 -0400 Received: from mail-wg0-f49.google.com ([74.125.82.49]:36573 "EHLO mail-wg0-f49.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751200AbbGLXOZ (ORCPT ); Sun, 12 Jul 2015 19:14:25 -0400 MIME-Version: 1.0 In-Reply-To: <559D2688.5020302@gmail.com> References: <21611.1436179798@turing-police.cc.vt.edu> <559D2688.5020302@gmail.com> From: Matteo Croce Date: Mon, 13 Jul 2015 01:13:44 +0200 X-Google-Sender-Auth: 6ko9wgkb5HxD7-7uHV8rb9mlxvQ Message-ID: Subject: Re: [PATCH v2] add stealth mode To: Austin S Hemmelgarn Cc: Valdis Kletnieks , Nicolas Dichtel , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 2360 Lines: 65 2015-07-08 15:32 GMT+02:00 Austin S Hemmelgarn : > On 2015-07-06 15:44, Matteo Croce wrote: > Just to name a few that I know of off the top of my head: > 1. IP packets with any protocol number not supported by your current kernel > (these return a special ICMP message). Right, I'll handle them > 2. SCTP INIT and COOKIE_ECHO chunks when you have SCTP enabled in the > kernel. Well, I've never played with SCTP before > 3. Theoretically, some IGMP messages. > 4. NDP messages. > 5. ARP queries looking for the machine's IP addresses. Yes I know, but it's unlikely to receive this packets from WAN, right? My flag is intended to be used mostly on WAN interfaces, machines in LAN should be easily discoverable IMHO > 6. Certain odd flag combinations on single TCP packets (check the > documentation for Nmap for more info regarding these), which I believe > (although I may be reading the code wrong) you aren't accounting for. I've tried many TCP flags combination with hping3, NUL, SYN/ACK, ACK, SYN/FIN, etc. They doesn't get any response when the flag is set > 7. DAD queries. Never looked at this packets, are a subset of NDP? > 8. ICMP address mask queries (which you also don't appear to account for). It's deprecated and actually it doesn't get any response already > This is by no means an exhaustive list, but all of them really should be > addressed if you want to do this properly. > > Thank you, -- Matteo Croce OpenWrt Developer _______ ________ __ | |.-----.-----.-----.| | | |.----.| |_ | - || _ | -__| || | | || _|| _| |_______|| __|_____|__|__||________||__| |____| |__| W I R E L E S S F R E E D O M ----------------------------------------------------- CHAOS CALMER ----------------------------------------------------- * 1 1/2 oz Gin Shake with a glassful * 1/4 oz Triple Sec of broken ice and pour * 3/4 oz Lime Juice unstrained into a goblet. * 1 1/2 oz Orange Juice * 1 tsp. Grenadine Syrup ----------------------------------------------------- -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/