Firewall Wizards mailing list archives
Re: Botnets, IRC servers and firewalls?
From: "M. Dodge Mumford" <dodge () dmumford com>
Date: Mon, 2 Feb 2004 17:29:00 -0500
Paul Robertson said:
Firewalls are certainly capable of blocking a lot of this stuff- and I don't believe that the problem is just home users- am I wrong, or do we have too many places with too lax a security policy anymore?
While the IRC traffic you mention may or may not be increasing[1], the
underlying problem you identify is not new. Firewall administration has
become so simple that many refuse to think about it. It's just the bad evil
people on the outside that holds administrator's attention.. Little
contingency is made for what happens when[2] someone gets in.
I was rather alarmed at one point a few years ago when a rival organization
scanned my network with SNMP traffic. I notified their whois point of
contact, and forwarded it up my management chain to be handled at that
layer. Eventually it got blamed on a buggy HP printer drivers[3], which is
innocent enough. But the it was frightening that a security software company
wouldn't filter outbound traffic.
[1] I can neither confirm nor deny, I don't have metrics.
[2] Specifically "when", not "if".
[3] They scanned the entire class A network they were installed on. That's
because HP has/had an entire class A themselves.
--
Dodge
Attachment:
_bin
Description:
Current thread:
- Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? M. Dodge Mumford (Feb 02)
- Re: Botnets, IRC servers and firewalls? Gwendolynn ferch Elydyr (Feb 02)
- Re: Botnets, IRC servers and firewalls? Barney Wolff (Feb 02)
- Re: Botnets, IRC servers and firewalls? Luca Berra (Feb 02)
- Re: Botnets, IRC servers and firewalls? Victor B. Williams (Feb 02)
- Re: Botnets, IRC servers and firewalls? Mordechai T. Abzug (Feb 02)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? Marcus J Ranum (Feb 02)
- Re: Botnets, IRC servers and firewalls? Mordechai T. Abzug (Feb 02)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? Gadi Evron (Feb 03)
- Re: Botnets, IRC servers and firewalls? M. Dodge Mumford (Feb 02)
