OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
FreeBSD Security Archives: Re: kernel patch to detect port scan

Re: kernel patch to detect port scan, without turning on ports...


Mark Newton (newtonatdot.dotat.org)
Sun, 24 Oct 1999 15:26:57 +0930 (CST)


A.G. Russell IV wrote:

> Sorry if this is redundant,
> I'm looking for the kernel patch to allow detection of a port scan without
> turning on each of the ports.

Execute the following

   sysctl -w net.inet.tcp.log_in_vain=1
   sysctl -w net.inet.udp.log_in_vain=1

You'll get a console log message whenever someone tries to reach a
port which isn't listening.

   - mark

--------------------------------------------------------------------
I tried an internal modem, newtonatdot.dotat.org
     but it hurt when I walked. Mark Newton
----- Voice: +61-4-1620-2223 ------------- Fax: +61-8-82231777 -----

To Unsubscribe: send mail to majordomoFreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



This archive was generated by hypermail 2.0b3 on Sun Oct 24 1999 - 00:58:58 CDT