Re: Need urgent help regarding security

看板FB_security作者時間20年前 (2005/11/26 03:09), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串33/36 (看更多)
> >Be careful with adding ip addresses to deny via a packet filter. > >If an attacker uses spoofed IP adresses, you may produce yourself > >easily a denial of service attack. > > Not sure I agree with the easily part. TCP transport plus SSH > protocol spoofing is not a vector that normally needs to be secured > beyond what is already done in the kernel and router. That's not to > say such spoofing cannot be done, just that it is rare and would > require a compromised router or localnet host at a minimum. Except that it doesn't require spoofed addresses. One attacker from the local university's computer center (or from a large shell service ISP) could lock out all of the other users on that machine. Trivially. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #13Xs6300 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #13Xs6300 (FB_security)