Re: securing a network with nfs

From: Derek D. Martin (ddm@mclinux.com)
Date: 08/13/01


Date: Mon, 13 Aug 2001 14:22:13 -0400
From: "Derek D. Martin" <ddm@mclinux.com>
To: "Welsh, Armand" <Armand.Welsh@sscims.com>
Subject: Re: securing a network with nfs
Message-ID: <20010813142212.C21831@mclinux.com>

Welsh, Armand said:

> I would deny all traffic by default. If you reject, then you are
> allowing the person on the outside to receive icmp-unreachable replies,
> making port scanning respond much faster. I prefer to run my firewalls
> in stealth mode, where they only respond on ports that they are actually
> using.

But, I will reiterate:

> Denying traffic to/from identd is sort of an un-Internet-friendly
> act... doing so will cause many Internet services (like sendmail, for
> example) to suffer (typically) 30-second timeouts with each connection
> as it waits for a response from the identd server.

And if you reject this one port out of 131,070, how much has it really
increased the speed of your port scan? Additionally, I mentioned
rejecting the port from ALL IPs in your address block, which
camouflages which hosts are actually there or not. This will
encourage attackers to scan hosts which aren't there, wasting far more
time than rejecting the one port will save them...

-- 
Derek Martin
Senior System Administrator
Mission Critical Linux
martin@MissionCriticalLinux.com



Relevant Pages

  • Re: SSO fails when machine is connected to network
    ... I added an entry to both the hosts and lmhosts files and I ... (this message came when I tried to delete the receive port to add it again) ... I have a named workgroup using the name of the machine. ... network adapter or add another explicit loopback) that is not 127.0.0.1. ...
    (microsoft.public.biztalk.server)
  • Re: Question on keeping Fedora 7 secure while connected to Internet
    ... to disable relaying from untrusted hosts). ... Telnet is available to two specific hosts only, ... The password guessing programs all ... attack port 22 so using a different port makes you invisible to them. ...
    (comp.os.linux.security)
  • Re: Should I configure a firewall to allow multicast?
    ... firewall is blocking various hosts to 192.168.1.255 port 138. ... but I know for certain there are no hosts with an address of 192.168.1.255. ... inet 192.168.1.9 netmask ffffff00 broadcast 192.168.1.255 ...
    (comp.security.firewalls)
  • Re: Discovering Live Hosts
    ... 1)You hint that your targets may be behind a firewall. ... until you actually connect to each and every port. ... Some hosts support no ... initial target pool is large. ...
    (Pen-Test)
  • RE: Subseven Scans
    ... A Sequentially Distributed RECON probe for SubSeven V 2.1 port 27374 started ... The analyses proved that 23 seperate hosts were used for the attack. ... >RK> For more information on this free incident handling, management ...
    (Incidents)

Quantcast