Re: How to get rid of spoofed IP-Address responses

From: jon schatz (jon@divisionbyzero.com)
Date: 05/24/02


From: jon schatz <jon@divisionbyzero.com>
To: Patrick Morris <pmorris@wilshire.com>
Date: 24 May 2002 13:25:02 -0700


On Fri, 2002-05-24 at 09:09, Patrick Morris wrote:
> The best defense against this sort of thing is to block all incoming
> traffic to your servers on ports > 1024. For machines acting strictly
> as servers, in most cases they shouldn't be getting high-port traffic
> anyway.

just to clarify, don't you mean:

"..block all traffic with the SYN flag set to your servers on ports >
1024"?

otherwise, most servers would not run correctly.

-jon

-- 
jon@divisionbyzero.com || www.divisionbyzero.com
gpg key: www.divisionbyzero.com/pubkey.asc
think i have a virus? www.divisionbyzero.com/pgp.html
"You are in a twisty little maze of Sendmail rules, all confusing." 




Relevant Pages

  • Re: Visa PCI Firewall Requirements and Windows Networks
    ... GP without the risk of open ports or a DC in the DMZ. ... Outbound access should be minimized but if windows update is your ... alternative tools on trusted servers to patch your machine. ... > behind the second firewall. ...
    (Focus-Microsoft)
  • Re: Win32 The RPC server is unavailable
    ... correct DNS servers and the port are unblocked. ... WMI errors the seem to be RPC related. ... All od the port are unblocked between the servers and the ... Usually RPC errors are due to name resolution or blocked ports. ...
    (microsoft.public.windows.server.networking)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Status Update - "Out of Paper" - HELP!
    ... Tcpip ports on the server. ... Windows Printing Team ... I've got 6 Windows 2000 print servers here. ...
    (microsoft.public.win2000.printing)
  • Re: Compromised Windows Server
    ... running exchange for one client. ... has been built, during the build it was not open to the internet. ... servers. ... You mention that the machine is an Exchange server, yet it has ports 80 ...
    (Incidents)