public inbox for gentoo-security@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-security] RE: port knocking
@ 2005-10-04 20:51 morgan allen
  0 siblings, 0 replies; 6+ messages in thread
From: morgan allen @ 2005-10-04 20:51 UTC (permalink / raw
  To: gentoo-security

nope, laptop -> wifi router -> iptable
-- 
gentoo-security@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread
* [gentoo-security] RE: port knocking
@ 2005-10-04 20:45 morgan allen
  0 siblings, 0 replies; 6+ messages in thread
From: morgan allen @ 2005-10-04 20:45 UTC (permalink / raw
  To: gentoo-security

Yes I have it setup to work only from lan side, but i
can work from the net side by tracerouting first, then
setting the ittl accordingly. And yes, unfortunatly it
does require special privleges.
-- 
gentoo-security@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread
* [gentoo-security] RE: port knocking
@ 2005-10-04 20:12 morgan allen
  2005-10-04 20:25 ` boger
  2005-10-04 20:31 ` Dan Gregory
  0 siblings, 2 replies; 6+ messages in thread
From: morgan allen @ 2005-10-04 20:12 UTC (permalink / raw
  To: gentoo-security

Here is a method I use to frustrate people trying to
nab my wifi connection using iptables (wireless router
-> linux router -> dsl -> net). The wireless router in
setup with a basic NAT for my desktops and wireless
but the wireless comes in on its own nic. with
prerouting set to drop, I have
[1:56] -A PREROUTING -m ttl --ttl-eq 202 -j ACCEPT

echo 204 > /proc/sys/net/ipv4/ip_default_ttl
on my laptop init

-- 
gentoo-security@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2005-10-04 22:01 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-10-04 20:51 [gentoo-security] RE: port knocking morgan allen
  -- strict thread matches above, loose matches on Subject: below --
2005-10-04 20:45 morgan allen
2005-10-04 20:12 morgan allen
2005-10-04 20:25 ` boger
2005-10-04 20:31 ` Dan Gregory
2005-10-04 21:57   ` Willie Wong

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox