16 messages in edu.merit.nanogRe: impossible circuit
FromSent OnAttachments
Jon LewisAug 10, 2008 8:15 pm 
George CareyAug 10, 2008 10:24 pm 
Laurence F. Sheldon, Jr.Aug 11, 2008 6:27 am 
Justin ShoreAug 11, 2008 1:16 pm 
Jay R. AshworthAug 11, 2008 1:22 pm 
list...@pwns.msAug 12, 2008 4:36 am 
Jon LewisAug 12, 2008 7:37 am 
Andy JohnsonAug 13, 2008 7:41 am 
Justin ShoreAug 13, 2008 9:02 am 
Jon LewisAug 13, 2008 9:29 am 
Andy JohnsonAug 13, 2008 11:27 am 
Jared MauchAug 13, 2008 11:33 am 
Jon LewisAug 16, 2008 11:07 pm 
list...@pwns.msAug 16, 2008 11:36 pm 
Jay HenniganAug 16, 2008 11:56 pm 
Paul WallAug 18, 2008 1:46 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:Re: impossible circuitActions...
From:Jay R. Ashworth (jr@baylink.com)
Date:Aug 11, 2008 1:22:05 pm
List:edu.merit.nanog

On Mon, Aug 11, 2008 at 03:17:18PM -0500, Justin Shore wrote:

The OS X update I applied was the one that installed a host-based firewall. The update automatically turned on the FW and permitted all local servers that were configured to run, in my case SSH, with everything else being denied. The FW on the OS X box normally wouldn't see packets not destined for it until you put a nic in promisc mode such as what happens when you run EtherPeek. The OS X box's FW was getting hits from traffic denied by it's ACL and was sending TCP RSTs faster than hosts on the 'Net could respond. It did this for everything except SSH which it permitted (but higher up the IP stack it ignored because the IP packet was address to the local box).

This isn't in any way related to the problem at hand but it does demonstrate that weird things happen when devices in unusual places flood out all ports.

And this explains why in Bellovin's Wily Hacker book, there's an anecdote about a sniffer machine on which they had to *physically cut the transmit wire* because they could *not* get the machine to not... do something. ARP queries?

Cheers, -- jra

Those who cast the vote decide nothing. Those who count the vote decide everything. -- (Josef Stalin)