FB_security 板


--Apple-Mail=_20AE229B-882B-44AF-BA93-4919477E8D81 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=windows-1252 On 21 Mar 2014, at 11:41, Info / RIT.lt <[email protected]> wrote: > Dear FreeBSD users, my first experience with FreeBSD was 14 years ago, = but due to hardware problems I chose Linux. After working with Linux for = 14 years, I decided to give a shot to FreeBSD again. After setting up = FreeBSD server with jails, I became a victim of DDoS which was launched = from my dedicated server, investigation led to NTP server, this = misconfiguration left with default settings shocked me, please fix this = configuration bug. >=20 > Firewall is for filtering traffic, but not for hiding buggy configs. >=20 > Regards, > Mindaugas Bubelis I kept silent so far, but this lets me frown a bit. We all know that there are people on the internet that try to hurt our = businesses, 24*7*365. All unprotected networks and hosts are targeted, 24*7*365. It is -very- common practise to setup a security perimeter, to only = allow traffic you want to have to your machine(s) and only let out traffic you want from your machine(s). I worked for = large scale ISP=92s, and we all did the same. Reading the mails from this thread leads me to believe that there is no = stateful firewall concept in place? Only allow the network you want to your NTP server(s) and deny the = others. Only let our your NTP server=92s to the internet to retrieve the date. Do that statefully and only traffic you send out should come back with = the last line mentioned, it is hard from the internet seen to hijack such a session and fool the firewall from letting the packet = back in to your NTP server. In my believing it is so that if you do not filter traffic, you are = making a deliberate choice to let everyone smack your service(s). That is not a problem but you also need to modify your configuration(s) = to make sure it is as safe as it gets. We (FreeBSD) updated the ntpd.conf file that is shipped as a Security Patch so that users = running our update facilities have that in place. However since people also change their configurations on their own or do not use that, = they need to be aware that they need to update the rules as well! We do not want to enforce our configuration changes to users who = might have a good reason for having an alternative setup! The only thing I saw from Brett that might need investigation is the = additional 'disable monitor=92, though would that break people=92s setup ? are people using that on purpose for some reason? Then we cannot = enforce it, just advice that this might be an solution to prevent issues. In my understanding and believing, stateful firewalling your networks is = the best option, making sure that only your own machines or a selected set of machines can access NTP resources on your network = (or the internet, whatever you prefer) and that traffic leaving your borders can only return if the firewall sees that you setup = the communication in the first place. In the above case: did you install the FreeBSD-release and never = updated? Then that is something -you- should have done. Installing something via delivered media is always out of date and needs to be = updated before first use. Thank you. Remko > ________________________________________ > From: [email protected] = <[email protected]> on behalf of Brett Glass = <[email protected]> > Sent: Friday, March 21, 2014 6:44 AM > To: Micheas Herman; [email protected] > Subject: Re: NTP security hole CVE-2013-5211? >=20 > At 10:38 PM 3/20/2014, Micheas Herman wrote: >=20 >> While true, that does mean that amplification attacks are limited to = being >> able to attack those ten machines. >=20 > The amplifier/relay is also a victim, and can be completely disabled = by the attack > if its link to the Net becomes saturated. >=20 > --Brett Glass >=20 > _______________________________________________ > [email protected] mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to = "[email protected]" > _______________________________________________ > [email protected] mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to = "[email protected]" --=20 /"\ Best regards, | [email protected] \ / Remko Lodder | remko@EFnet X http://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and News --Apple-Mail=_20AE229B-882B-44AF-BA93-4919477E8D81 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJTLB24AAoJEKjD27JZ84ywn1QP/1S8TeNgFM/WUKAtMVhcO7ij f6U4Dch4fEW+Z5xj9vWqL2rQ7spACWXDYGYa5EtdNMWNBUOtDAoqHPp6jkZdg9wq i5ZMj5N6NAKRt2lP48fzHqjNW8OM7ZHShzb+7azwZvoILBNXnS+l1iRljz7/+xL/ 4vGaj07H+Cbd8kh2A69BvXEmnDq7GKEPl1DDUe3L/LK1QckXIbe759Q+5Fq5/lC/ PdNqUOfseMNKAeZ4KVYqdoWPtCBQDy6Jt9x+m/8yfq3IOkAZp9AtGb1VPpiMcCEn yrwis/H6XGB0AlYt9VyXoQSFRHVN5V1q/SOWzPwaQ28xzHkZ5gV5uzPj9xMu8BQc kxJxDQ6T2Md3nUug/pW9YMMz7uJT0Lsaw2hjsko5r1dUzfGY7QZKciP5Hyix7FGS nK7W99GhTWzGqCVkdx0q+Yf6a8xMT8sUEk+IoOU55RJ3zyhrJgAtl1Zv/3IfJE+i GRV5RzH37aHyk6TjuJk5T2mYckqdKFvNRdaY5CV+l9tEogVKo6z6aW9g8tTYJRkk DeHd1jZpVKhjFiwg6epIeh4GW3ijK+Rp/vyGm6i/OheG62j3Y+Kuus87OMb3+7m9 cKwhfzbKNMVjmWKOprKYP47Wi+BZmqvr2e+A96iWxSFIjV17w59VcrYNGxVrDIFe l3EiqWYCuA0Iz6YHob4E =2fay -----END PGP SIGNATURE----- --Apple-Mail=_20AE229B-882B-44AF-BA93-4919477E8D81--







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草
伺服器連線錯誤,造成您的不便還請多多包涵!
「贊助商連結」






like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:e-shopping站內搜尋

TOP