Re: SSH security questions

From: Menno Duursma (pan_at_desktop.lan)
Date: 05/12/05


Date: Thu, 12 May 2005 11:55:26 GMT

On Thu, 12 May 2005 09:03:57 +0400, Mikhail Zotov wrote:
> Menno Duursma wrote:

>> ALL EXEPT sshd : .com, .net, .org, .edu, .gov, .mil, .int, .biz, \
>> .aero, .coop, .museum : DENY
>>
>
> I am afraid this is not a perfect solution

Indeed it's not. Haveing it spawn a whois query looking for Country: US
would narrow it down some more (the database for which should be local.)

> because the fact that a host has a name with a edu|com|org|net suffix
> doesn't guarantee that it is located in the US.

Well, to me it seem(s/ed) the objective is/was to filter (drop?) the bulk
of packets obviously unwelcome. So an administrator can concentrate on the
ones the fliter let trough.

And anyways, filtering on IP adress wouldn't guarantee a host to reside in
some contry or other either. As the AS to which it belongs might be
distributed, rerouted, or there maybe some kind of VPN tunnel in use, etc.

-- 
-Menno.


Relevant Pages

  • Re: Knee Surgery...
    ... He is getting released Jun 1 in a cap move. ... included a no trade clause and a guarantee that if I ever lead ... "There is nothing patriotic about hating your country, ... President Clinton 5 May 1995 ...
    (rec.sport.football.college)
  • Re: Filtering the underlaying table from a forms init or open methods
    ... Do you want to be able to set the "Country" dynamically or do you want it to ... I am assuming you are using Paradox for windows v7 or greater. ... >> select filter and set the filter you want. ... >>> It is not difficult to set a filter on the underlaying table to a form. ...
    (comp.databases.paradox)
  • Re: Knee Surgery...
    ... trade clause and a guarantee that if I ever lead the group in off topic ... "There is nothing patriotic about hating your country, ... President Clinton 5 May 1995 ...
    (rec.sport.football.college)
  • Re: IP Block assigned to a country
    ... >> assigned to a country. ... > perhaps it would be easiest for you to just filter the cidr blocks ... > from which you see attacks originating, ... > if all the packets come from a fairly small address space you should ...
    (comp.unix.admin)