Re: how to change OS idenfication?

From: Juraj Ziegler (e_at_hq.sk)
Date: 02/20/04


Date: Fri, 20 Feb 2004 10:39:08 +0100
To: Christophe Sahut <CleeK@nogoa.org>


On Wed, Feb 18, 2004 at 08:41:29PM +0100, Christophe Sahut wrote:
> The other way is to look like another operating system and then receive
> exploits that don't work on us, but this still be security through
> obscurity which is bad (tm).

I would rather rephrase it to "Security solely through obscurity is
bad." [tm]. If you secure your system on other layers and then _add_ an
obscurity layer, I see nothing wrong with it.

j.

-- 
_______________________________________________________________________________
>e@hq.sk<                   /(bb|[^b]{2})/                 >http://hq.sk/~euro<
           "najlahsi sposob ako chodit po vode je urobit z nej lad"




Relevant Pages

  • Re: Curious enough to know?
    ... Security by obscurity is no security at all. ... If that other operating system has a better permission system, and users aren't continually working with super user privileges then that will help, but just its obscurity doesn't. ... Just sitting back and thinking no viruses and malicious code exist for me so I don't have to worry about security is like saying my house has never been broken into, ...
    (uk.railway)
  • RE: Concepts: Security and Obscurity
    ... resources are limited and thus there is a cost to life. ... It is not obscurity in the manner being ... more you spend on security the less of an advantage is gained. ... It also ignores the requirements of a control function. ...
    (Security-Basics)
  • RE: Re: Concepts: Security and Obscurity
    ... so long as you understand that the server location and port number ... security in the slightest." ... Beale's assertion that "Obscurity Potentially Slows Down the Attacker". ... BDO Kendalls is a national association of separate partnerships and entities. ...
    (Security-Basics)
  • Re: NAT external/Public IP
    ... I remember working for an ISP a long while back that was threatened to be disconnected from the Internet if they did not stop routing the 10.x range in their BGP tables. ... Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. ... Why not Security by Design plus Security by Obscurity? ...
    (Security-Basics)
  • [Full-Disclosure] w32.frethem.k@mm and good reading
    ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
    (Full-Disclosure)