Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 13 Aug 1998 10:01:26 -0500 (CDT)
From:      John Preisler <john@vapornet.net>
To:        freebsd-chat@FreeBSD.ORG
Subject:   Re: UDP port 31337
Message-ID:  <199808131501.KAA07137@nitromethane.vapornet.net>
In-Reply-To: <Pine.SOL.4.02.9808131048280.17130-100000@banshee.cs.uow.edu.au>
References:  <199808121700.LAA00346@lariat.lariat.org> <Pine.SOL.4.02.9808131048280.17130-100000@banshee.cs.uow.edu.au>

next in thread | previous in thread | raw e-mail | index | archive | help

moved to -chat where it belongs

also,

while countermeasures seem like a neat idea, it doesnt make you
Part Of The Solution, it makes you Part Of The Problem.  More of the
same is not the answer in an attack on your service.  

-j

Nicholas Charles Brawn writes:
 > On Wed, 12 Aug 1998, Brett Glass wrote:
 > 
 > > If someone's trying to BO you, they deserve worse.
 > > 
 > > How about a daemon that sends fatal packets back TO the machine running BO?
 > > I'm sure that these punks haven't protected their code adequately against
 > > buffer overflows, etc.
 > > 
 > > --Brett
 > 
 > The company formerly known as SNI (now integrated into NAI) wrote a
 > paper on Intrusion Detection Systems a while ago which discouraged this
 > attitude. Their argument focused on the fact that what if someone
 > *knows* that this is the response that will be sent if your daemon
 > detects a connection attempt. Don't forget how easily udp packets can be
 > forged...
 > 
 > Nick
 > 
 > --
 > Email: ncb05@uow.edu.au - http://rabble.uow.edu.au/~nick 
 > Key fingerprint =  DE 30 33 D3 16 91 C8 8D  A7 F8 70 03 B7 77 1A 2A
 > "When in doubt, ask someone wiser than yourself..." -unknown
 > 
 > 
 > To Unsubscribe: send mail to majordomo@FreeBSD.org
 > with "unsubscribe security" in the body of the message
 > 

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-chat" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199808131501.KAA07137>