Re: Best way to filter "Nachi pings"?

From: David G. Andersen (danderse_at_cs.utah.edu)
Date: 10/27/03

  • Next message: Gaspar Chilingarov: "Re: Best way to filter "Nachi pings"?"
    Date: Mon, 27 Oct 2003 09:32:47 -0700
    To: Brett Glass <brett@lariat.org>
    
    

    Brett Glass just mooed:
    > At 03:17 AM 10/27/2003, Jarkko Santala wrote:
    >
    > >Blocking
    > >all ping packets to improve security is nothing more than security through
    > >obscurity. It may hide your system against the simplest ping probes, but
    > >it does nothing to improve security as such.
    >
    > In our case, there's a more compelling reason.
    >
    > Some of our customers' system administrators have utilities
    > which ping their servers from their home Internet connections
    > to make sure everything's working. If I were to block pings,
    > all of these guys' (and gals') pagers and cell phones would go
    > off at once. I'd be beseiged with demands to remove the block
    > immediately.

      Rate-limit them with dummynet on somewhat selective per-subnet
    basis. It's not perfect, and increases the latency perceived by
    customers running ping, but it helps a lot compared to doing
    nothing.

      -dave

    -- 
    work: dga@lcs.mit.edu                          me:  dga@pobox.com
          MIT Laboratory for Computer Science           http://www.angio.net/
          I do not accept unsolicited commercial email.  Do not spam me.
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Gaspar Chilingarov: "Re: Best way to filter "Nachi pings"?"

    Relevant Pages

    • Re: Removing ping/icmp from a network
      ... vendors / admins / whatever. ... A ping sweep isn't the only way to do network exploration. ... which won't gain you any security. ...
      (Security-Basics)
    • Re: WMI/COM and ExecNotificationQueryAsync for Win32_NTLogEvent
      ... because such computer excluded from the network the ping would fail. ... So it seems that I need to set up security ... thing or a WQL query issue, ... listener via ExecNotificationQueryAsync in a C++/COM environment, ...
      (microsoft.public.win32.programmer.networks)
    • Re: Best way to filter "Nachi pings"?
      ... >all ping packets to improve security is nothing more than security through ... >obscurity. ... If I were to block pings, ...
      (FreeBSD-Security)
    • Re: NTP, ntpdate, and ISP-based firewall
      ... >> barriers beyond the basic firewall. ... > Layered defenses are indeed the correct way to build up security. ... > mechanisms like ping, traceroute and tcpdump. ... > Put a firewall in front of your local network. ...
      (Fedora)
    • Re: Port Knocking questions
      ... >> Does it require the hacker to be able to ping the device? ... > application using port knocking requires an ICMP packet to be in the ... I suppose we can assume that "being able to ping" means ... Security Linux, the comprehensive security solution that combines six ...
      (Security-Basics)