Re: [fw-wiz] terminal services

From: Barney Wolff (barney@pit.databus.com)
Date: 01/28/03


From: Barney Wolff <barney@pit.databus.com>
To: firewall-wizards@honor.icsalabs.com
Date: Tue Jan 28 19:21:02 2003

On Tue, Jan 28, 2003 at 06:56:21PM -0500, Paul D. Robertson wrote:
>
> (UDP 1434)
> It's an ephemeral port- just blocking it may make random stuff not work in
> some situations (like say DNS...)

Any network without a state-keeping firewall between it and the Internet
really needs to have just one or two DNS cacheing proxies doing requests
from port 53, ditto NTP, and block all other UDP. Anything else is just
too dangerous, not by a little, but by a whole lot.

This worm sent from random source ports, but the next one will surely
send from 53 or 123, and all the folks who have allow any 53 to any
rules will get hit. Together with the folks who have allow any 20 to any.
Some things just can't be done safely without state, so if you need to
do them, you need to keep state.

-- 
Barney Wolff         http://www.databus.com/bwresume.pdf
I'm available by contract or FT, in the NYC metro area or via the 'Net.


Relevant Pages

  • Re: DSL Modem ?
    ... The folks who ran the wire to YOUR "home" location. ... I'm not comforted by comparing to NIS.. ... Would NOT even dream of using M$oft Network anything.. ... So most of my "Security" efforts involve disabling as much as I CAN.. ...
    (alt.computer.security)
  • Re: SPP and the Trans Texas Corridor
    ... I've never delved into 'black helicopter crap'. ... That big network of roads.... ... those folks who claim to be abducted by aliens. ... If your cites were worth anything, ...
    (rec.autos.driving)
  • Re: wireless hotel nightmare
    ... >> at a suspiciously default range like 192.168.0.1, nothing resembling the ... >> address in use by most folks on the network. ... I'm not sure how many boxes there are responding to 192.168.0.xxx. ...
    (alt.internet.wireless)
  • Re: newbie question | prevent ICMP timestamp requests
    ... He mentions that my box is responding to ICMP ... in an attempt to keep our IT folks happy - what is the easiest way ... > to prevent ICMP timestamp requests? ... /etc/sysctl.conf and then restart the network. ...
    (comp.os.linux.security)
  • Re: Pocket PC - Windows Startup issue - Posting 3rd time :((
    ... The folks who provide answers here are almost always volunteers, ... executable accesses the network to get some details. ...
    (microsoft.public.pocketpc.developer)