Firewall Wizards mailing list archives

Re: Looking for "lease based popper access"


From: sedwards () sedwards com
Date: Sun, 12 Dec 1999 16:14:40 -0800 (PST)

The IP address is not used for authentication. The idea is to limit a
[l]user who will not be authenticted from even being able to establish a
connection to the service -- if the "script kidz" can't connect, they
can't hack.

On Sun, 12 Dec 1999, Rodney van den Oever wrote:

I use tcp wrappers a lot when I configure client networks. I figure if the
script kiddies can't connect, they can't do a lot of damage -- assuming
tcp wrappers isn't exploitable :)

This works pretty good for most services except POP. Traveling employees
need to get to their email from where ever they are.


Then use a SSH- or SSL-based encrypted tunnel as is often discussed on this
list. You should not authenticate users based on their IP-address.

--
Rodney van den Oever / +31 318 695558 / PGP Key ID 0x0A6CCE53
'Bother' said Pooh, as he called in an air strike.

Thanks in advance,
------------------------------------------------------------------------
Steve Edwards      sedwards () sedwards com      Voice: +1-760-723-2727 PST
Newline            Pager: +1-888-478-5085           Fax: +1-760-731-3000



Current thread: