2004/12/2-4 [Computer/Networking] UID:35157 Activity:moderate
12/2    I used the "ShieldUp" website to probe my Mac and it shows that port 0
        and 1 are replying to outside query to say they are closed instead of
        just playing deaf like the other lower ports do.  I did not single
        out port 0 and 1 in the ipfw rules I use.  What rules should I use to
        close this loophole?
        \_ First off, don't use random pages like that, as Steve Gibson is
           an idiot.  Next, use a real port scanner like nessus or nmap.
           Next, why not just explicitly drop 0/1 like your ipfw manual
           says, if it bothers you?  The only thing drop vs block will do is
           make it a bit more difficult to probe for active IPs.  -John
           \_ What's your critique of Steve Gibson? -nop
               \_ He's a publicity junkie (fine) who comes up with complex-
                  looking "solutions" for simple problems (also fine) and
                  tries to pass them off as the BEST/ONLY way to do things.
                  He's done a lot of security-related fear mongering in the
                  past as well (no different from big vendors) in his
                  sensationalist carneval style.  One good example is his
                  when Windows XP came out--he made a huge fuss about how
                  raw socket access would bring the Internet to a halt.  SG
                  is a self-proclaimed expert who lives for press and panders
                  to lowest-common-denominator fears about security shit that
                  people wouldn't need to worry about, given a tiny bit of
                  common sense and willingness to RTFM.  Look at
                  for some comments--he is not a fraud, just really really
                  annoying and misinformed.  -John
                  \_ You said "raw socket access."  huh huh huh huh.
                  \_ I remember reading the "raw socket access" bit (before I'd
                     ever done socket programming) and not understanding it.
                     What exactly was he talking about?
                     \_ He's essentially saying that it's now easier for
                        kiddies to unleash mass DoS because XP makes it
                        simple(r) to not use TCP/IP drivers which
                        normally deal with socket access.  It's complete
                        mumbo-jumbo, but I encourage you to draw your own
                        confusions.  It's easy to find on google.  -John
           \_ Thanks but I also want to know why my computer is blocking
              port 0 and 1 instead of denying them when none of my ipfw
              rules used unreach/reject instead of deny.  Since I am using
              cable modem, could it be the modem that is blocking? -op
              \_ Unlikely, as a cable modem is usually just a kind of bridge.
                 What model/mfgr?  Have you now tried explicitly telling ipfw
                 to drop these to see what happens?  I'll gladly help you, but
                 why not take it to mail?  -John
