Re: Controlling ports used by natd

From: Barney Wolff (barney_at_databus.com)
Date: 12/13/03

  • Next message: Brett Glass: "Re: Controlling ports used by natd"
    Date: Fri, 12 Dec 2003 21:18:13 -0500
    To: Brett Glass <brett@lariat.org>
    
    

    On Fri, Dec 12, 2003 at 06:17:46PM -0700, Brett Glass wrote:
    >
    > In practice, I think we need to come up with something better than the
    > notions of "well-known" and "privileged" ports. Something that, unlike
    > portmap, is easy for firewalls to work with.

    It's not so easy, because malware is not likely to be so polite as to
    keep to fixed source ports. In fact, your real problem is with lazy
    firewalls that can't tell UDP responses from requests. A stateless
    firewall is an ACL, not a firewall. That works not so badly for TCP
    but is simply inadequate for UDP.

    -- 
    Barney Wolff         http://www.databus.com/bwresume.pdf
    I'm available by contract or FT, in the NYC metro area or via the 'Net.
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Brett Glass: "Re: Controlling ports used by natd"

    Relevant Pages

    • Re: How to practice with...
      ... >networking, switches, routers, firewalls, etc. ... >Could you tell how can I still closer of these boxes? ... He would look at equipment ... enough so he could practice. ...
      (comp.security.firewalls)
    • Re: [fw-wiz] Isolating internal servers behind firewalls
      ... clients behind firewalls? ... What benefits might we gain from the practice? ... What threats are we protected from? ... I asked google for more information - you asked this question before, ...
      (Firewall-Wizards)
    • Re: Sam Spade Says Personal Firewalls are Snake Oil
      ... >>firewalls" quite obviously doesn't satisfy it. ... >Would you be so kind as to quote one for me, ... there is no difference between theory and practice. ...
      (comp.security.firewalls)
    • Re: Anti-security product designed to break firewalls
      ... >The widely respected Cryptome website has recently posted some leaked ... >details of an anti-firewall product, developed by Codex, designed to ... According to the info on the website it doesn't attack real firewalls, ... there is no difference between theory and practice. ...
      (comp.security.firewalls)