RE: DShield.org Recommended Block List

From: Ken Kousky (kkousky_at_ip3inc.com)
Date: 04/29/03

  • Next message: ullmic: "Lotus Cross-Certification"
    To: "'Bob Kelley'" <b0bk3ll3yjr@adelphia.net>, <security-basics@securityfocus.com>
    Date: Mon, 28 Apr 2003 20:23:57 -0400
    
    

    We showcase this site to clients and promote it but I think you'll still
    have to manually supervise the blocked site list.

    Key issue here is to make sure you don't post mega proxy ip addresses to
    your ACLs and block a lot of your market ... which means you need to
    apply a manual review of what you're posting.

    Also, an exploit of a legitimate site might knock out legit clients. It
    wasn't that long ago that ISC2 was hijacked which placed them on a lot
    of blocked lists.

    KWK

    -----Original Message-----
    From: Bob Kelley [mailto:b0bk3ll3yjr@adelphia.net]
    Sent: Friday, April 25, 2003 1:27 AM
    To: security-basics@securityfocus.com
    Subject: DShield.org Recommended Block List

    I am looking for some feedback on using the dshield recommended block
    list
    on my screening router which sits in front of my firewall. Those who
    wish
    to respond...Do you find it helpful/beneficial/essential? Also, what
    methods are you using to keep the associated access-list up to date? Is

    this a purely manual process? Do you do this daily, weekly ?
    Thanks...Bob

    ------------------------------------------------------------------------

    ---
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam,
    the 
    world's premier event for IT and network security experts.  The two-day 
    Training features 6 hand-on courses on May 12-13 taught by
    professionals.  
    The two-day Briefings on May 14-15 features 24 top speakers with no
    vendor 
    sales pitches.  Deadline for the best rates is April 25.  Register today
    to 
    ensure your place.
    http://www.securityfocus.com/BlackHat-security-basics 
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most 
    recognized corporate security certification track, provides a comprehensive 
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization 
    of pertinent security tools. For a limited time you can enter for a chance 
    to win one of the latest technological innovations, the SEGWAY HT. 
    Log onto http://www.securityfocus.com/FastTrain-security-basics 
    ----------------------------------------------------------------------------
    

  • Next message: ullmic: "Lotus Cross-Certification"

    Relevant Pages

    • RE: SharePoint Services V3, permissions for People and Group lists
      ... I tried the group security and it worked really well when you click on a ... members but still see everyone by just clicking "all people". ... works with multiple clients, and they need a way to share files with clients ... so calendars / events lists. ...
      (microsoft.public.sharepoint.portalserver)
    • RE: PAWS security vulnerability
      ... FreeBSD security list" isn't grammatically correct. ... "I told you to post the patch and info to the appropriate FreeBSD security ... "...This point and others are often discussed on the mailing lists, ...
      (freebsd-questions)
    • May I have permission to travel???????
      ... ""Homeland Security Tightens Grip on International Travel ... The Department of Homeland Security proposed new rules back in July ... These lists ... Instead of providing a passenger manifest after departure as now ...
      (alt.true-crime)
    • RE: PAWS security vulnerability
      ... You STILL haven't taken this to the correct security mailing list, ... > FreeBSD security ... >>lists, and you aren't the least bit interested in doing what ... >>appropriate forum to post the patch, ...
      (freebsd-questions)
    • RE: SharePoint Services V3, permissions for People and Group lists
      ... If someone knew anything about SharePoint, ... works with multiple clients, and they need a way to share files with clients ... The new security trimmed ... so calendars / events lists. ...
      (microsoft.public.sharepoint.portalserver)