Should or shouldn't block public ping to a website
- From: ShiYih Lye <shiyih.lye@xxxxxxxxxxxxxxxx>
- Date: Mon, 5 Sep 2011 14:03:57 +0800
Hi,
All this while I'm not allowing any public ping to the website I'm
maintaining, but it's making me tougher to troubleshoot should any
user from the globe having trouble to access our website, as I can't
make them to send a proper traceroute report.
To your opinion, is it necessary to block public ping to a public
website ? Is this security practice still relevant in today exploit
technology ?
And if you think it's still necessary, how do I make sure my user's
traceroute still work when all ICMP is dropped from public ?
Thanks for any input, appreciated that.
Regards,
Lye
------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
http://www.iacertification.org
------------------------------------------------------------------------
- Prev by Date: Web app assignments.
- Next by Date: Insomnia: Whitepaper - LFI With PHPInfo Assistance
- Previous by thread: Web app assignments.
- Next by thread: Insomnia: Whitepaper - LFI With PHPInfo Assistance
- Index(es):