Re: Best way to filter "Nachi pings"?

From: Brett Glass (brett_at_lariat.org)
Date: 10/28/03

  • Next message: G. Panula: "Re: /var partition overflow (due to spyware?) in FreeBSD default install"
    Date: Mon, 27 Oct 2003 19:05:38 -0700
    To: peter.lai@uconn.edu
    
    

    At 12:22 PM 10/27/2003, Peter C. Lai wrote:
      
    >Similarly, is there a reason that you wouldn't be able to use the less robust
    >ipfw2 on your release (since I assume you'd be using it purely for its iplen
    >capabilities)?

    Look at some of the latest notes in the CVS database. They mention
    use-after-free problems, security holes (unprivileged users can
    manipulate the firewall), and other things you just wouldn't want
    on a production system. The good news is that they scoured the code
    quite thoroughly, and it seems to be solid now.

    --Brett

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: G. Panula: "Re: /var partition overflow (due to spyware?) in FreeBSD default install"

    Relevant Pages

    • Re: system crash during file copy to a floppy with bad sectors
      ... this is generally a question of resilience of individual file systems to on-disk corruption and failures. ... UFS is quite tricky to make robust against disk destruction, since it relies on strong consistenty guarantees for performance reasons. ... FAT, on the other hand, is a file system we should be able to make more robust quite a bit more easily. ... The reason FAT is particularly interesting, of course, is its widespread use on removable media such as USB sticks. ...
      (freebsd-stable)
    • Re: message buffering for logs, sprintf, etc...
      ... The software security business would be a lot smaller and duller if ... code "to be robust against people deliberately trying to sabotage" it. ... Most people believe that anything that is true is true for a reason. ...
      (comp.lang.c)
    • Re: Flaky SCSI drive - software solution?
      ... >>I recently bought a cheap 40GB SCSI drive. ... Turned out the reason it was ... Is there anything more robust than mkfs to format this ...
      (comp.os.linux.misc)
    • Re: On the subject of Self Promotion....
      ... The reason I'm wondering where I'd put a ... The current one is still going to be cheaper to run and more robust on ... big jobs than any colour laser cheap enough to be worth buying. ... straight black and white printer. ...
      (rec.arts.sf.composition)