 |
 |
Panther built in Firewire not stealthing Port 0 and 1 Need to fix it!
|
 |
|
 |
|
Mac Elite
Join Date: Aug 2000
Location: Vancouver B.C.
Status:
Offline
|
|
I am trying to lock down my moms computer, and port 0 and 1 show up as closed. I did a new rule in the sharing panel unchecked it and that didn't work. Any idea's on how to put these 2 ports into stealth using the build in firewall, without disabling the ability to control it via sharing?
|
Get busy living or get busy dying --Stephen King
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Oct 1999
Location: :ИOITAↃO⅃
Status:
Offline
|
|
I really wouldn't worry about it. 2 useless ports being closed vs stealth isn't going to matter in any real sense.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Nov 2001
Location: Trafalmadore
Status:
Offline
|
|
You had me really confused thinking you were trying to stealth your Firewire ports !
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Aug 2000
Location: Vancouver B.C.
Status:
Offline
|
|
Originally posted by Mithras:
I really wouldn't worry about it. 2 useless ports being closed vs stealth isn't going to matter in any real sense.
It is important to my mom, and me. I want her computer completely blind to any port scan, and her ISP has a 5GB/month cap so every attack costs $$$. Her computer needs to be 100% stealth, and those ports show up on scans.
|
Get busy living or get busy dying --Stephen King
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Oct 2001
Location: San Diego, CA, USA
Status:
Offline
|
|
Are you sure they're visible to the wider world and not just people in your subnet or something along those lines?
|
|
Chuck
___
"Instead of either 'multi-talented' or 'multitalented' use 'bisexual'."
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Dec 2000
Status:
Offline
|
|
Originally posted by Chuckit:
Are you sure they're visible to the wider world and not just people in your subnet or something along those lines?
If you go to grc.com and do a full port scan there, they always show ports 0 and 1 as being closed, so yeah.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Jul 2002
Status:
Offline
|
|
Panther's firewall isn't capable of stealthing anyway, so I don't know what you're talking about. And a port scan is a trivial amount of bandwidth. They'd have to be hitting you pretty damn hard for those pings to add up to much.
|
|
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Nov 1999
Status:
Offline
|
|
Originally posted by Thinine:
Panther's firewall isn't capable of stealthing anyway, so I don't know what you're talking about. And a port scan is a trivial amount of bandwidth. They'd have to be hitting you pretty damn hard for those pings to add up to much.
Actually, Panther's firewall is capable of stealthing. Apple's firewall interface doesn't set it to do that by default, but third-party configurators like BrickHouse can do it with no trouble.
|
|
You are in Soviet Russia. It is dark. Grue is likely to be eaten by YOU!
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Jul 2002
Status:
Offline
|
|
|
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Dec 2000
Status:
Offline
|
|
Originally posted by Millennium:
Actually, Panther's firewall is capable of stealthing. Apple's firewall interface doesn't set it to do that by default
Huh? Yes it does. Just not for ports 0 and 1.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Oct 2004
Location: Downtown Austin, TX
Status:
Offline
|
|
Wouldn't a cheap router put in front of the computer be better in saving bandwidth? You would configure the router not to respond to ping attempts and then close all inbound ports. You could easily find a router online for under $15.
|
|
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Nov 1999
Status:
Offline
|
|
Originally posted by jamil5454:
Wouldn't a cheap router put in front of the computer be better in saving bandwidth?
No, because ISPs assess their charges when the data is sent to your computer, not when your computer actually gets it. The router would block the ping from getting to your machine, but it would still have been sent, and so you'd still be charged.
The only thing a stealth firewall can do is slow down a port scan, by making sure that the scanner has to wait for timeouts on every ping instead of just getting a "Connection refused" response. However, usually someone using scanner will simply give up after a couple of pings, and that is how bandwidth gets saved; only ten or so pings get through instead of some 36,000.
|
|
You are in Soviet Russia. It is dark. Grue is likely to be eaten by YOU!
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Aug 2000
Location: Vancouver B.C.
Status:
Offline
|
|
Does anyone have an answer? Maybe the problem will be fixed in Tiger?
|
Get busy living or get busy dying --Stephen King
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|