Re: NTP, ntpdate, and ISP-based firewall

From: Rodolfo J. Paiz (rpaiz_at_simpaticus.com)
Date: 03/05/04

  • Next message: Alan Horn: "Re: Firewall"
    To: fedora-list@redhat.com
    Date: Fri, 05 Mar 2004 13:29:55 -0600
    
    

    At 18:09 3/4/2004, you wrote:
    >It doesn't make me more of a target to return 'ICMP prohibited' packets in
    >reply to probes at prohibited ports. On the contrary it probably makes me
    >less of a target because I clearly have active security measures in place.

    Disagree. To most crackers, it makes you more interesting. And not
    answering anything, as Joanne said, will reduce by a large amount the
    number of people who take the time to decide that the silent host is worth
    probing further. Also read my "Real-time blocking with Portsentry" note for
    how to use portsentry, iptables, and a simple shell script to totally
    banish offenders from your system.

    -- 
    Rodolfo J. Paiz
    rpaiz@simpaticus.com
    http://www.simpaticus.com
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Alan Horn: "Re: Firewall"

    Relevant Pages

    • RE: Malformed DNS or something odd (or just me)
      ... There are several different similar types of probes, ... The second UDP port is identical for all probes to any target address. ... - The payloads of the packets generally have IP addresses embedded in them. ...
      (Incidents)
    • Re: JSH: Surrogate factoring, periodic behavior
      ... and there is a lot wrong with this example from my standpoint as ... It factored the target with 160 probes: ... would remove repeats of those small factors - which is where repeats ...
      (sci.math)

    Loading