看板FB_security
标 题Re: Attacks on ssh port
发信站NCTU CSIE FreeBSD Server (Sun Sep 19 06:06:19 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
Willem Jan Withagen <
[email protected]> probably said:
> I also have portsentry in a rather sensitive mode doing exactly the same
> thing.
> Trigger one of the "backdoor" ports, and you're out of my game.
The general problm with this type of reactive filtering is that if
someone can spoof the source addresses effectively or cause a connection
from a legitimate host you've just DoSed yourself...
Personally I only allow ssh from known legitimate sources and block the
rest so the "noise" is in a completely different list.
P.
--
pir
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"