看板FB_security
標 題Re: NTP security hole CVE-2013-5211?
發信站NCTU CS FreeBSD Server (Fri Mar 21 20:20:37 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
In message <
[email protected]>,
Remko Lodder <
[email protected]> wrote:
>Reading the mails from this thread leads me to believe that there is no
>stateful firewall concept in place?
I am not the poster to whom you were responding (
[email protected]), however
speaking only for myself I will confess that yes, in my case at least,
although I have used ipfw for many years, I have never (until now) found
any compelling need to either understand or make use of any of ipfw's
stateful capabilities.
>In my believing it is so that if you do not filter traffic, you are
>making a deliberate choice to let everyone smack your service(s).
I personally *do* most certainly filter traffic, and have done, since
I first connected *any* machine of mine to the Internet. I can assure
yoy that I never made any deliberate choice to let everyone smack me
around. Nontheless, that clearly did happen, eventually, when evil-doers
decided, relatively recently, to use & abuse me as an NTP reflector, but
my participation in this was not in any sense deliberate on my part, and
arose strictly out of ignorance, for which I am suitably humbled and
apologetic.
Regards,
rfg
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"