Pings and how to block them.
17 min read
That requires some kind of Firewall capable of true stealthing. or block
ping requests as Ztruker have shown.
When stealthing, a firewall ignores any request on contacting the line.
The firewall silently ignores packets sent to forbidden (closed) hosts
or ports. Including ping requests. dropping the packets.
True stealth Firewalls does sent a message back…Confused?
Let me explain:
When "people" pings in the wild, they are searching for ports. A closed port
will report just that, that it is closed. and the "pinger" will know something is
there, but its closed. (like a closed and locked door) A port that is off-line will
respond with a ICMP (Internet control message protocol) saying
"Host unreachable". Normal stealth Firewalls simply drops the packets, therefore
returning no message, which is standing out like a beacon in the dark.
If nothing truly weren't there, the message would be "host unreachable". So the pinger
will know something is there, just not what it is (what Firewall type / brand etc.) and
therefore wouldn't know right away what attack would be best.
Some true stealth firewalls does sent this message, and therefore it appears off-line,
which would discourage the would-be attacker to pursue the attack. Unless he knows
you are there, and is after you
A determined and knowledged attacker won't be fooled by stealth / true stealth if he knows
you are supposed to be there! But for the average hacker and the wannabe's, its enough
to discourage, and they will move on to easier prey. Have in mind that they maybe ping 1000's
of ports in a short time, and any unanswered or "unreachable host's" will drown in the sea.
So stealth only protects you better, by trying to go unnoticed. A closed port, by a
strong non-stealthing Firewall will also discourage any attackers, unless as said,
that they are specifically after you. It could take hours trying to open a closed
firewall, hardly worth the time when there is so much easier prey readily at hand.
Hope this shed some light, and that it is not all to confusing
regards Abydos
Reason for edit: Saw Ztruker's after I posted
So are you saying that standing out like a beacon in the dark makes you more vulnerable? I mean like it is worse than the message "host unreachable" (discouraging others because it is like nothing is there and it does not exist)?"Host unreachable". Normal stealth Firewalls simply drops the packets, therefore
returning no message, which is standing out like a beacon in the dark.
If nothing truly weren't there, the message would be "host unreachable". So the pinger
will know something is there, just not what it is (what Firewall type / brand etc.) and
therefore wouldn't know right away what attack would be best.
Basic rule (we all know) is that a firewall is always better than no firewall. To simply put it, when you install a software firewall it will automatically stealth ports for you (Comodo Pro was shown blocking incoming connections)? And would you say it's "true" that Stealth Ports are more "secure" than closed ports?
Er, its a bit confusing since it was a busy week for me.
Learning everyday. Thank you all.
So are you saying that standing out like a beacon in the dark makes you more vulnerable? I mean like it is worse than the message "host unreachable" (discouraging others because it is like nothing is there and it does not exist)?
I wouldn't put it that way.
Closed Ports: Return message that it is closed.
Stealthed Ports: Return no message because it drops the packets, which is not a normal internet protocol behavior.(therefore making it all the more suspicious)
True stealthed Ports: Returns message "Host unreachable", which is the same message you get with a off-line port.
To simply put it, when you install a software firewall it will automatically stealth ports for you (Comodo Pro was shown blocking incoming connections)?
Only if capable of stealthing, and for some you have to activate it. In Comodo you have to activate it, Firewall –>Stealth Port Wizard. Even then, it will tell you "blocked" altho it just dropped the packets. It will still be closed, like a normal closed port
if any tried to gain access.
And would you say it's "true" that Stealth Ports are more "secure" than closed ports?
No. Only in the sense that they are harder to detect. That is, what type of Firewall.
Let me try again. When you have a stealth port, and someone try to ping you, they will come back with a "host unreachable" message?
If capable of True Stealth, yes. Normal stealthed firewalls just drops the packets. Leaving attackers in the dark as to what Firewall might be in place. Therefore complicating best attack approach because the attacker have to feel his way. Firewalls without stealth, are plain in sight, leaving no doubt to the attacker what he is facing.
Learning everyday. Thank you all.
Don't we all? One way or another
Hope its more understandable this time around.
i should also add, that this is my understanding
of it, I might have some things wrong mind you.
But poke around the internet, and see what you can
learn
regards Abydos
Abydos, I want your answer on some programs that handle these "True Stealth Ports". Haha, well it sounds a bit vague. In other words, you can list some programs that offer true stealth port protection? I think Comodo Pro Firewall has one, but I'm not quite sure how to configure it. I think the 3rd Option for the Stealth Port Wizard might work (do you use Comodo Pro Firewall)?
I guess Windows Firewall will be just as useless as if there is no firewall. Some users give their doubts about ZoneAlarm too.
But I really do think that installing any firewall will automatically activate their stealthing feature. Haha
Conclusion: True Stealth>Stealthed>Closed>No Firewall. Agreed? : D
Only two app's I can think of on the fly that have True Stealth are Comodo Pro.3.0 (2.4 don't, which are used by win 2k users)
and Online Armor (which is almost as strong as Comodo!). Both are free to boot. Other than that, I think one would have to look for paid Firewalls to get true stealth.
(do you use Comodo Pro Firewall)?
Yes. Have used it since version 2.4, and never looked back
Altho I have tested some various Firewalls on my test / Surf machine in a Virtual enviroment.
I won't come with any definite opinions on various Firewalls, as it would sound biased….
Hope you understand. But I can say that windows Firewall isn't much worth imo. The Vista
Firewall is slightly better than XP.
But I really do think that installing any firewall will automatically activate their stealthing feature. Haha happy.gif.
Ehmmm, no…
Conclusion: True Stealth>Stealthed>Closed>No Firewall. Agreed?
Yes. Altho the strength of a Firewall is measured in how good it is to keep things out (or in) and not if it have stealth or not.
If you want to get a feel about the strengths of the various Firewalls out there, then you could visit this site
from time to time. They test on a regular basis. Altho, don't rely 100% on the info, but use it as said, to get
an overall picture.
http://www.matousec.com/projects/firewall-…nge/results.php
Regards Abydos
Thank you for link
No problem
I did think about what you said… Firewall strength is measured on how well it keeps things in and out but not the stealth features?
CPF turned to CIS, and they have drastically improved so much.
Read the section about "Interpretation of results" in the link I gave you. Valueable info there!
All the tested products have one common feature – the application based security model. In combination with their packet filtering capabilities, the tested products attempt to block attacks from other machines on the network as well as attacks performed by malicious codes that might run inside the protected machine. This is definitely not an unusual situation. People who use email clients, instant messengers, or web browsers face attacks that exploit the vulnerabilities in this kind of software very often. It happens that a malicious code gets inside the machine. And then it may try to install itself silently to the system, to steal users' data or sniff their passwords, or to join the target machine to the botnet. This is what the products we test, called personal firewalls, want to prevent. This is why they are used. The problem is that although the goal is common, not all the products implement a sufficient protection.
If you download and install crackware containing malware for example, you actually give the malware a free passage letter if your AV or Firewall don't sniff them out or if one ignores the alarm-bells. In that situation, stealth won't do you no good. Stealth is only vs. direct attacks on your line. And let me tell you, that doesn't happen very often.
Also be sure to understand what the tests are about, and not base ones opinion on the fancy-colored table shown alone.
I know, lot of it sounds like gibberish to the untrained, but its enough to begin understand what Personal Firewalls are about.
Bottom-line is, stealth or no stealth, doesn't matter in the big picture. Its the firewalls software coding that matters, and it is that
a firewalls strength is based upon. How good is it to keep malware away from your door-step, thats what matters. Stealth is over-rated as security. Sure, use it if your Firewall is capable of it, but don't base your choice of defense upon it.
I am rambling on here, its early morning
Hope you can make head and tail of it.
Regards Abydos
So it's basically saying that this "stealth" feature is overrated (clique?) HahaIf you download and install crackware containing malware for example, you actually give the malware a free passage letter if your AV or Firewall don't sniff them out or if one ignores the alarm-bells. In that situation, stealth won't do you no good. Stealth is only vs. direct attacks on your line. And let me tell you, that doesn't happen very often.
![]()
Also be sure to understand what the tests are about, and not base ones opinion on the fancy-colored table shown alone.
I know, lot of it sounds like gibberish to the untrained, but its enough to begin understand what Personal Firewalls are about.
Bottom-line is, stealth or no stealth, doesn't matter in the big picture. Its the firewalls software coding that matters, and it is that
a firewalls strength is based upon. How good is it to keep malware away from your door-step, thats what matters. Stealth is over-rated as security. Sure, use it if your Firewall is capable of it, but don't base your choice of defense upon it.
I am rambling on here, its early morning![]()
Hope you can make head and tail of it.
Regards Abydos
I understand now so Firewall strength is based on how well it controls the traffic, like allowing things in and out and defending us against attack.
Stealth would only be effective if it is an attack directed to my connection, and Firewall can't defend you if you are purposely infecting yourself with cracks.
That sums it up?
-
Hm, my Comodo Pro Firewall seems to have a stealth option but I'm still having trouble passing the ShieldsUp! test because it tells me that I am still responding to the Ping.
Don't worry about it, I kind of get the picture. When we're tired our concentration might not be so good as when we're awake.
I appreciate your knowledge and your help.
That sums it up?
Also, be aware that the site I linked, they use their tests. The results are based upon their
test-results, which is why I said you shouldn't rely 100% on the results.
Glad you could use the info.
Regards Abydos
Thank you. And I have no idea whatsoever on the tests they perform. It's like you gotta be a genius or rocket scientist to perform those… "ShadowHook" and "Runner" leak tests O_O
-
Er, well I wanted to ask you something Abydos.
Do you have the "Stealth Ports Wizard" configured/activated in your Comodo Pro Firewall 3.x?
Yes I have it activated.
I quote myself:
Sure, use it if your Firewall is capable of it, but don't base your choice of defense upon it.
Regards Abydos
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI