Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 7 Oct 1999 18:55:25 -0400
From:      "David Simsik" <dsimsik@vt.edu>
To:        "security@freebsd.org" <freebsd-security@freebsd.org>
Subject:   Programming Contest
Message-ID:  <NDBBIFDFMMKJLMPMMJAHAEJMCAAA.dsimsik@vt.edu>

next in thread | raw e-mail | index | archive | help
Hello all

I was recently hired to help run a regional Programming contest that takes
place every year.  My job is to set up some low level security so that the
contestants cannot get in contact with each other and/or someone on the
outside world.  To explain the structure of our site we will have two
FreeBSD servers running (one on a pent200 machine and one on a pent75
machine) which will run parts of the judging software.  Both servers are Ver
3.3-Release.  The clients which will run the client side of the judging
software will be borrowed from one of our labs.  to my knowledge they are
using an older version of FreeBSD running on Gateway P5-200s.  The Network
will be set up within the lab and the structure of the Ethernet cannot be
changed.  Also I do not have access to their gateway or their servers.

My original plan was to set up one of the servers (P75) as a gateway/site
server.  This server would authenticate the users on the client machines and
then would control the packets going outbound.  The problem is that while
using this gateway by defining it in the Client machines and a firewall on
the gateway I can control what machines the clients can send packets to but
cannot control the inbound packets.

With this said I have two questions.  :
1. If the Gateway on the client machines is my machine is there any way for
the clients to get around the gateway and if there is then is there a way I
can stop that?  (send packets in a way so they don't go through the gateway
server)

2. what daemons would you recommend I shut off so that the contestants
cannot get in contact with each other. (telnetd, ftpd,...)

Any recommendations for solutions are welcome.


Thank you
David Simsik
Regional Systems Team Leader
tech@midatl.cs.vt.edu



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?NDBBIFDFMMKJLMPMMJAHAEJMCAAA.dsimsik>