Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 13 Jun 1999 17:54:06 -0400
From:      "Gary Palmer" <Gary.Palmer@RCN.COM>
To:        Jay Nelson <jdn@acp.qiv.com>
Cc:        "Ed P." <secure@r0ck.com>, security@FreeBSD.ORG
Subject:   Re: Fwd: [linux-security] Re: Port 7 scan 
Message-ID:  <34083.929310846@noop.colo.erols.net>
In-Reply-To: Your message of "Sun, 13 Jun 1999 14:24:50 CDT." <Pine.BSF.4.05.9906131348450.801-100000@acp.qiv.com> 

next in thread | previous in thread | raw e-mail | index | archive | help
Jay Nelson wrote in message ID
<Pine.BSF.4.05.9906131348450.801-100000@acp.qiv.com>:
> The echo service is, AFIK, a peculiarly Unix service. Why do you
> suppose they chose echo for the latency test as opposed to a simple
> ping? Nearly everything with an ethernet card will respond to a ping
> returning, I would think, more useful latency information than a
> refused connect.

No, not everything. Most of the systems at work can't be pinged (with
some exceptions). 'Course, you can't get to their echo port either.

> Since echo is Unixcentric and most new admins leave echo open, echo
> will reveal far more about a machine than a ping. Could it be that
> this is the intent?

Having talked to Resonate about their distributed load balancing
stuff, apparently some customers asked for echo port queries rather
than ICMP (from memory ... the meeting was a couple of months ago).  I
think many many people are blocking ICMP at their borders to protect
from smurfs.

Basically, if you didn't understand the previous reply (or need more
info) Resonate make a couple of DNS based load balancing solutions,
one for replacing DNS round robin in a single datacenter environment,
one for distributing load across multiple datacenters, with traffic
being sent to the `closest' one.  Their distributed DNS system works
by having a system at each of the datacenters `ping' (somehow) the DNS
server doing the lookup. The one with the lowest latency (generally,
although load at the datacenter, and local preferences, can also weigh
in) will be chosen, and an A record for ad.doubleclick.net will be
returned pointing at that datacenter. Generally, that A record will be
pointing at their local load balacing solution, which is an entire
other story.

Gary
--
Gary Palmer                                          FreeBSD Core Team Member
FreeBSD: Turning PC's into workstations. See http://www.FreeBSD.ORG/ for info


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?34083.929310846>