Re: Honeypot stats



In article <11sbge4k57q1339@xxxxxxxxxxxxxxxxxx>, Dave Froble <davef@xxxxxxxxxxxxx> writes:
> Larry Kilgallen wrote:

>> As for "open new ports", that vulnerability is a characteristic of
>> TCP/IP where unprivileged users can set up a port to accept incoming
>> connections without authorization. On DECnet adding some corresponding
>> vulnerability requires privilege.
>
> Well Larry, today's reality is TCP/IP. Even so, a user with no privs,
> opening a non-priv port, cannot affect the rest of the system any more
> than said user could without using TCP/IP.

Crashing the system is not the only possible security problem.
Unauthorized modification or release of data is actually more
important in most cases, and keeping unauthorized users from
permitting that which is forbidden is essential to maintaining
control of a system.

With DECnet one knows that no normal user has created some path
for unauthenticated connections.
.



Relevant Pages

  • Re: ReadPrinter fails for TCP/IP port, works for LPT1 and USB using pjlmon XP DDK sample
    ... > a printer that's connected via TCP/IP. ... The printer port we're using is ... > to the language monitor, and ReadPrinter returns with a 0 meaning that ... but did work with direct TCP/IP connections. ...
    (microsoft.public.development.device.drivers)
  • Re: Adding a TCP/IP printer
    ... TCP/IP capability with my VMS 5.4. ... The printer does NOT speak DEC proprietary protocols such as DECnet and LAT. ... The other alternative is to connect it to a PC style parallel port which are somewhere between very rare and non-existent on VAX and Alpha! ...
    (comp.os.vms)
  • Re: Multiplexing serial data for multiple applications
    ... COM port between two running applications. ... TCPCom is primarily designed to expose a COM port to a TCP/IP port ... willaccept multiple client connections. ...
    (microsoft.public.pocketpc.developer)
  • Re: z/OS using a guest virtual LAN under z/VM
    ... Making the DEVICE name the same as the TRLE name does *not* correspond to what I just posted on the IBMTCP-L list concerning the relationship between the TRLE statement and the DEVICE statement. ... The device name must be the PORT name of the LAN adapter defined in a TRLE for a QDIO connection. ... OSA port operating in either ATM native mode or in QDIO mode. ... If used by TCP/IP, this name must also be defined as the portname in the TCP/IP Profile DEVICE statement. ...
    (bit.listserv.ibm-main)
  • Re: VPN problems
    ... But assuming you want to let people at the office access something else through the VPN tunnel, your easiest method is to set up one Linux box as a router so that everyone's traffic passes through that box and out. ... Anyway, you shouldn't be letting people with Macs connect directly to broadband - and certainly not people with Windows - especially in your case, you should assume the broadband connection is full of evil hackers and worms. ... Only protocols on top of UDP and TCP/IP have ports. ... One of the nice things with OpenVPN is that it uses UDP and so you can easily change the port if you want. ...
    (comp.os.linux.networking)