FB_security 板


--Apple-Mail=_7154F1F9-7C28-40EA-BF8B-62041B9AE070 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=windows-1252 On 21 Mar 2014, at 20:20, Ronald F. Guilmette <[email protected]> = wrote: >=20 > In message <[email protected]>,=20 > Remko Lodder <[email protected]> wrote: >=20 >> Reading the mails from this thread leads me to believe that there is = no >> stateful firewall concept in place? >=20 > I am not the poster to whom you were responding ([email protected]), however > speaking only for myself I will confess that yes, in my case at least, > although I have used ipfw for many years, I have never (until now) = found > any compelling need to either understand or make use of any of ipfw's > stateful capabilities. Hi Ronald, That is =91fine=92 ofcourse but makes you vulnerable to the =91crap=92 = that is hitting your doorway now. Rest assured that you are already doing a great step = in at least filtering your machines and as you demonstrate you are active on the internet to get the information you need to do it properly. That is = already way better then a lot of other people. A question that pops my mind: Do you think we (security people) needed = to be more verbose about why this might have been a good idea? or could we = have done a better job in reasoning why stateful has it=92s advantages? >=20 >> In my believing it is so that if you do not filter traffic, you are >> making a deliberate choice to let everyone smack your service(s). >=20 > I personally *do* most certainly filter traffic, and have done, since > I first connected *any* machine of mine to the Internet. I can assure > yoy that I never made any deliberate choice to let everyone smack me > around. Nontheless, that clearly did happen, eventually, when = evil-doers > decided, relatively recently, to use & abuse me as an NTP reflector, = but > my participation in this was not in any sense deliberate on my part, = and > arose strictly out of ignorance, for which I am suitably humbled and > apologetic. Let me offer my apologies, I did not want to make you feel ignorant or = anything. What I meant is that everyone should filter on their machines, or if = possible even ahead of their machines at the gateways. Stopping traffic you do = not want should occur at the border so that it never ever reaches the machines it = is not supposed to reach. People do make a living in =91pestering=92 you and I (and many others) = and now smacking your NTP server(s) is gaining them something, or they wouldn=92t = just do it. My best advice in this case might be that only allowing in the networks = you want to have in on your NTP server (Stateful) prevents people that you = do not want to have their in the first place. Only letting out the traffic you = want (also stateful) prevents bogus replies because they most likely are = caught at the firewall already. Ofcourse the software should be well protected as well, and secteam@ did = his best to offer the best solution possible. Though as mentioned by Brett = for example we just cannot force the update of ntpd.conf on user machines = because every admin could have legitimate reasons for having a configuration in = place they decided to have. It=92s risky to change those things and especially = enforce them on running machines. Most of his ideas were in the advisory already except for the =91disable monitor=92 part, which might be reason to = discuss whether that makes sense or not. Thank you, Remko >=20 >=20 > Regards, > rfg > _______________________________________________ > [email protected] mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to = "[email protected]" --=20 /"\ Best regards, | [email protected] \ / Remko Lodder | remko@EFnet X http://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and News --Apple-Mail=_7154F1F9-7C28-40EA-BF8B-62041B9AE070 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJTLK73AAoJEKjD27JZ84ywMpcQAKINH2ZhAOthD+12a6acMRG4 5cDfWQb//28/2Brzxx7O7V/VANxW2gkd+FU+nNP8jaE0yQYfWufEPz4u8ZHqgfJy hPDCenASgYUJ189vJBODl7WMJw0vpr0mHnK9LEf9VXAX6Y/KhdL5kYxeHSL3qhOk um72FOqXRry10XttgIIu3aNToNqkV6rbfQp7eHmbsCl/eetN5XDAGnqmr5DKBeLq WUcwqhuzGPpPQtINH7+sQ24PFE8YtRUP7nIVhIXgffIy+iBMP6J4JY2SUIvyRxtk SeaLyMhXHW26e3SRTkC6gHhOgS3BsMeOhmSB7OMG3sLPOBw0m4bw1tVAK35nMMws CqCACV2O3JYr3u9ThlNl7Hke6oCl8P4f3N8LKaWjrH5KLvR6ci9ApLKv2lhFWAzQ eJN5Xr9ghEzqctsIEeKXgeh+tIqMSDTSsmVrIwV3lgK9tLLtTcnOQ+NouC7IdJa+ 5bu8kqfir1/Ih8A9Dh93IKFodzoNGQgN4j0HGtceqWig6BDxopcpycaANYZm/qLw v9xxsWzuuwuaALfJv1Z/I5EEsjn59UaF8AM0jiE4L8piTq70Zc19KLUTA496zX5/ +8q5jQN9yLxfMkXyjrWSZq0lJGGH8/LLMuCvyXZOdnLuiYSVr6O+qz0DlzxSIJ4g SjAbXlt1cFY3V+mxIgvV =nHAw -----END PGP SIGNATURE----- --Apple-Mail=_7154F1F9-7C28-40EA-BF8B-62041B9AE070--







like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草
伺服器連線錯誤,造成您的不便還請多多包涵!
「贊助商連結」






like.gif 您可能會有興趣的文章
icon.png[問題/行為] 貓晚上進房間會不會有憋尿問題
icon.pngRe: [閒聊] 選了錯誤的女孩成為魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一張
icon.png[心得] EMS高領長版毛衣.墨小樓MC1002
icon.png[分享] 丹龍隔熱紙GE55+33+22
icon.png[問題] 清洗洗衣機
icon.png[尋物] 窗台下的空間
icon.png[閒聊] 双極の女神1 木魔爵
icon.png[售車] 新竹 1997 march 1297cc 白色 四門
icon.png[討論] 能從照片感受到攝影者心情嗎
icon.png[狂賀] 賀賀賀賀 賀!島村卯月!總選舉NO.1
icon.png[難過] 羨慕白皮膚的女生
icon.png閱讀文章
icon.png[黑特]
icon.png[問題] SBK S1安裝於安全帽位置
icon.png[分享] 舊woo100絕版開箱!!
icon.pngRe: [無言] 關於小包衛生紙
icon.png[開箱] E5-2683V3 RX480Strix 快睿C1 簡單測試
icon.png[心得] 蒼の海賊龍 地獄 執行者16PT
icon.png[售車] 1999年Virage iO 1.8EXi
icon.png[心得] 挑戰33 LV10 獅子座pt solo
icon.png[閒聊] 手把手教你不被桶之新手主購教學
icon.png[分享] Civic Type R 量產版官方照無預警流出
icon.png[售車] Golf 4 2.0 銀色 自排
icon.png[出售] Graco提籃汽座(有底座)2000元誠可議
icon.png[問題] 請問補牙材質掉了還能再補嗎?(台中半年內
icon.png[問題] 44th 單曲 生寫竟然都給重複的啊啊!
icon.png[心得] 華南紅卡/icash 核卡
icon.png[問題] 拔牙矯正這樣正常嗎
icon.png[贈送] 老莫高業 初業 102年版
icon.png[情報] 三大行動支付 本季掀戰火
icon.png[寶寶] 博客來Amos水蠟筆5/1特價五折
icon.pngRe: [心得] 新鮮人一些面試分享
icon.png[心得] 蒼の海賊龍 地獄 麒麟25PT
icon.pngRe: [閒聊] (君の名は。雷慎入) 君名二創漫畫翻譯
icon.pngRe: [閒聊] OGN中場影片:失蹤人口局 (英文字幕)
icon.png[問題] 台灣大哥大4G訊號差
icon.png[出售] [全國]全新千尋侘草LED燈, 水草

請輸入看板名稱,例如:Boy-Girl站內搜尋

TOP