|
-
February 16th, 2006, 11:08 AM
#1
Johnno,
Technically, a computer that doesn't exist would be seen as "All ports Filtered", because no response could be elicited from any port because they aren't there thus appearing to be a firewall dropping the packets.
I think by the fact that Relyt quoted me, (thanks mate), that most here know that this is a huge bugbear of mine... This is what makes me laugh hard:-
Total elapsed testing time: 5.006 seconds
“PASSED” TruStealth Analysis “PASSED”
Phhht... Say what???? In 5.006 seconds GRC scanned my entire box, TCP, UDP and ICMP across the internet and has determined that the box doesn't exist. Damn, that man is a genius. 65,355 ports, twice, (TCP and UDP remember), in 5 seconds... quite remarkable. No it's not, a few years ago I did a packet capture on GRC to see what it was they did do... It wasn't very much at all... Certainly, in the sense of _knowing_ whether a computer was there or not it was dismally lacking. GRC checks a few, and I mean a few, of the common ports with a heavy emphasis on NetBIOS, (because that's where his "scanner" was born out of IIRC), and then he makes his "proclaimation". Despite the fact that every Trojan in the world could be listening on any port it likes other than the few he tests he still proclaims you as safe. And that's what bugs the bejeebers outta me. Poor old Joe Public just got a clean bill of health just the same as he does from his Dr. and so he's happy till his next annual physical - all the while the cancer is eating away at him because, like GRC's scan, the Dr. doesn't test for everything in the annual physical - just the common things...
Now let's compare the blurbs of the two "providers" used.
DSLReports stated:-
Conclusion: Healthy Setup! We could detect no interesting responses from any of the commonly probed TCP and UDP ports. It would be difficult for an attacker to know where to start without further information.
Ohh.. Look... Look... That looks quite "honest"... It states it could _detect_ "no interesting responses"... That's fair. But it goes on... "from any of the _commonly_ probed...". There, see.. No hype.. DSLReports states up front that it didn't do everything... Just the common ports. Then it says the last sentence... Which is absolutely accurate...
Ok... Let's look at GRC...
Your system has achieved a perfect "TruStealth" rating. Not a single packet — solicited or otherwise — was received from your system as a result of our security probing tests. Your system ignored and refused to reply to repeated Pings (ICMP Echo Requests). From the standpoint of the passing probes of any hacker, this machine does not exist on the Internet. Some questionable personal security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. But your system wisely remained silent in every way. Very nice.
Now... Everyone take a deep breath please.... Can you smell the bullshit too???? I don't think I need to take it apart piece by piece - we're all smart enough to see the difference.
Where I come from the difference is called "responsibility"... GRC falls sadly short... Funnily enough I do believe it was dear Mr. Gibson that coined the term "Stealth"... Now it's getting a bit worn out he's hyped it up again - now it's TruStealth... 'Nuff said?
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|