Re: ipfw and it's glory...

From: Bart Matthaei (bart@dreamflow.nl)
Date: 07/17/02


Date: Wed, 17 Jul 2002 13:10:29 +0200
From: Bart Matthaei <bart@dreamflow.nl>
To: "Carroll, D. (Danny)" <Danny.Carroll@mail.ing.nl>

On Wed, Jul 17, 2002 at 12:44:51PM +0200, Carroll, D. (Danny) wrote:
> I disagree with te 1024-65535 rules.
> In my experience you can get it to work without allowing all of these.

Some things tend to break when you leave it out. I can't give you any
examples atm, since I don't recall them :)

> Plus the way you have it setup, if you ever have X running then port
> 6000 is open and I really hate that idea.

Then add deny rules for port 6000 :)

Cheers,

Bart

-- 
Bart Matthaei                 bart@dreamflow.nl 
If at first you don't succeed, redefine success.
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: Win32, Linux, .NET >> Where is this mess going to?
    ... I respectfully disagree. ... properties/methods will not port without modification. ... The Mono project will not port the ... Mono, so only some apps, or some parts of apps will port easily. ...
    (borland.public.delphi.thirdpartytools.general)
  • RE: sshd listening on port 6010
    ... Just disable X11 forwarding if you dont want it. ... sshd listening on port 6010 ... Does anyone know why sshd listens on port 6010 when someone is ssh'd ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • RE: Kernel message
    ... It can block them via tcpwrappers, or even add a route for them using ... Somebody was portscanning you - running a simple program that connects ... port, not open) messages, and it had a max value of 30 of those per second. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Timecounter "TSC" frequency
    ... date/time. ... The message you had the day before looks like a port scan of ... > (changed just in case of security holes) ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: SGID make
    ... installed without using the port. ... The reason for the sgid'ness is most likely so that the binary can ... query the system load average to optimize parrallel compliation ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)

Quantcast