Re: Policing user CGI scripts

From: Bodo Eggert (7eggert_at_fsmtpd.7eggert.dyndns.org)
Date: 07/05/04


Date: Mon, 05 Jul 2004 03:23:47 +0200

Walter Roberson <roberson@ibd.nrc-cnrc.gc.ca> wrote:
> all mail refused <elvis@notatla.org.uk> wrote:

> :For instance I like webservers to accept TCP traffic on just
> :2 ports (80, 22) and cannot originate any TCP traffic at all.
[..]

> But it also breaks DNS. UDP based DNS is only good up to 512
> bytes per record, and when a longer record would be returned,
> a flag is set in the result; at that point, the originating
> system is supposed ot retry with TCP based DNS.

There is no real need for DNS on a web-server.

-- 
"Violence is the last resort of the incompetent."       -- Isaak Asimov (1920-1992)
"Damn straight. The competent don't wait that long."    -- Jerry Pournelle
Friß, Spammer: buch@edvbuchmarkt.de mailing@interchemist.com


Relevant Pages

  • Re: Policing user CGI scripts
    ... Walter Roberson wrote: ... > bytes per record, and when a longer record would be returned, ... > a flag is set in the result; ... There is no real need for DNS on a web-server. ...
    (comp.security.misc)
  • Re: Policing user CGI scripts
    ... :2 ports and cannot originate any TCP traffic at all. ... But it also breaks DNS. ... bytes per record, and when a longer record would be returned, ...
    (comp.security.unix)
  • Re: Policing user CGI scripts
    ... :2 ports and cannot originate any TCP traffic at all. ... But it also breaks DNS. ... bytes per record, and when a longer record would be returned, ...
    (comp.security.misc)