RE: Possible New Security Tool For FreeBSD, Need Your Help.

From: Laurence Brockman (L.Brockman@videon.ca)
Date: 09/05/01


From: Laurence Brockman <L.Brockman@videon.ca>
To: security@freebsd.org
Date: Wed, 5 Sep 2001 15:41:02 -0600 


> -----Original Message-----
> From: Chris BeHanna [mailto:behanna@zbzoom.net]
> Sent: Friday, August 31, 2001 10:08 PM
> To: security@freebsd.org
> Subject: Re: Possible New Security Tool For FreeBSD, Need Your Help.
>
<SNIP>
> If your machine is attached to a cable modem, then there are 253
> other hosts in your neighborhood who can very easily sniff
> your traffic.

This is wrong in all but the worst Cable Modem Provider cases. Most modems
communicate directly with the cable routers and do not broadcast ANY traffic
but the broadcast traffic (ARP's, etc). You could sniff the RF on all of the
modems on your node, but this should all be encrypted anyways (At least the
Cable provider I work for does this, as well as most others that I know of).
So, if your Cable provider is not filtering traffic, etc then I'd have a
talk with them. It's very easy now days to implement filters on the cable
modem (Including the dropping of spoofed packets to prevent things like
SMURFs, etc).

>
> If you're trying to open ports remotely, then your key traffic is
> going over the internet. Do a traceroute between the host you're
> using and the host you're trying to manage, and ponder someone
> sniffing along any of those hops.
>
> Although this is unlikely for the casual user, it becomes more
> likely if the remote host is a corporate-owned machine in a highly
> competitive area of industry.
>
> --
> Chris BeHanna
> Software Engineer (Remove "bogus" before
> responding.)
> behanna@bogus.zbzoom.net
> I was raised by a pack of wild corn dogs.
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Remote Desktop Connection
    ... via hub which gets a DHCP address from the modem, ... Since I have DSL at the host I downloaded and installed on the host the ... as to attemps for the remote computer to login. ... Al Jarvi (MS-MVP Windows Networking) ...
    (microsoft.public.windowsxp.network_web)
  • Re: Q: IP addresses for interfaces and SBS 2003 (and more)
    ... Jim Behning SBS MVP wrote: ... > The only way to avoid lightning surges if they are direct hits is, ... > jumps in to an external modem then it can keep jumping through the db9 ... > or someone like godaddy host it. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant connect to web sites
    ... Have cable modem with a router. ... pinging google and yahoo resulted in "could not find host" ...
    (microsoft.public.windowsxp.general)
  • Re: Assistance with DWL-2700A access point
    ... (wired connection or wireless) ... we can get back by reseting the modem. ... I can ping the D-Link 192.168.0.2 port but not the 192.168.01 Qwest ... Host router appears to be up. ...
    (alt.internet.wireless)
  • =?Utf-8?Q?Re:_webseite_ver=C3=B6ffentlichen_-_m?= =?Utf-8?Q?al_etwas_TRICKY?=
    ... Wenn ich auf dem Host eine PPPoE Verbindung erstelle klappt es. ... Das Modem ist kein Router. ... Er arbeitet nur mit Portforwarding. ... Was Du beschreibst, ist ein DSL-Router. ...
    (microsoft.public.de.german.windows.server.networking)