Security Incidents mailing list archives
Re: traffic logging
From: damian () ITACTICS COM (Damian Gerow)
Date: Tue, 9 May 2000 14:53:58 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Hello, I'm the author of the PortSentry software and would like to add some comments to this thread.Humm... I don't much care for PortSentry's retaliationsequence. Thesuggested action (blocking the route, adding offending host to hosts.deny, setting up a firewall rule to deny alltraffic coming fromthe offending host) really turns me off - it creates anice, simple DoSon it's own.A lot of people say this and the scenario is stated many times in the software documentation in the interest of full-disclosure for the user. From the actual field-use perspective, I've never heard of this problem being a serious issue from any user at all. In other words I've had absolutely zero complaints of actual attacks doing this that weren't related to direct hostile activity against a host. The DoS issue is simply not relevant from the field deployments I've seen. FWIW.
I personally have never had any problems with it either, I'm just saying that problems can arise quickly, if the attacker figures out the actions being taken. -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com> iQA/AwUBORheOvWPEBDMsfC4EQJRjwCggND1dKUBTOCCCZb/XH80sjf0QWEAoOP4 a0i4W1Ie2GnldDrU2QbNlEgp =N5pW -----END PGP SIGNATURE-----
Current thread:
- Re: traffic logging Scott McClelland (May 01)
- <Possible follow-ups>
- Re: traffic logging Damian Gerow (May 03)
- Re: traffic logging spiff (May 08)
- Re: traffic logging Craig H. Rowland (May 08)
- Re: traffic logging Jason Baker (May 08)
- Re: traffic logging spiff (May 08)
- Re: traffic logging Robert G. Ferrell (May 03)
- Re: traffic logging Erich Meier (May 04)
- Re: traffic logging Damian Gerow (May 09)