Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Proxy 2.0 secure? (IDS)

Re: Proxy 2.0 secure? (IDS)

From: <tqbf_at_pobox.com>
Date: Tue, 7 Jul 1998 14:24:57 -0500 (CDT)

> make your firewall do the packet reassembly, leave your IDS in passive
> monitoring so that it does not become the object of an attack.

If you implemented this right (and that's not easy), you might solve the
fragmentation problem. Now solve the TCP stream reassembly problem.

-----------------------------------------------------------------------------
Thomas H. Ptacek SNI Labs, Network Associates, Inc.
-----------------------------------------------------------------------------
http://www.pobox.com/~tqbf "If you're so special, why aren't you dead?"
                                        
Received on Jul 08 1998

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos