Re: [fw-wiz] stealth ports and IDS

From: Paul D. Robertson (probertsat_private)
Date: Thu Oct 03 2002 - 08:55:07 PDT

  • Next message: Kevin Steves: "Re: [fw-wiz] stealth ports and IDS"

    On Thu, 3 Oct 2002, Zen wrote:
    > 	You can ifconfig the interface giving address.
    Some OS' might source packets from that address, that's probably a bad 
    idea, no address is better than ""
    > > mitigate it I am looking at hardware network taps (read only). These
    > > could be the answere but are not that cheap (kind of the whole idea).
    > 	Just crimp an ethernet cable with only the rx couple.
    Most modern switches and cards won't do the right thing without a TX lead 
    due to autonegotiation of speed/duplex settings.  You might be able to get 
    around it by forcing settings, but it's ceratianly not the sure thing it 
    once was.
    Paul D. Robertson      "My statements in this message are personal opinions
    probertsat_private      which may have no basis whatsoever in fact."
    probertsonat_private Director of Risk Assessment TruSecure Corporation
    firewall-wizards mailing list

    This archive was generated by hypermail 2b30 : Thu Oct 03 2002 - 21:52:19 PDT