Firewall Wizards mailing list archives
Re: Botnets, IRC servers and firewalls?
From: "Mordechai T. Abzug" <morty () frakir org>
Date: Mon, 2 Feb 2004 21:13:36 -0500
On Mon, Feb 02, 2004 at 05:02:58PM -0500, Paul Robertson wrote:
Now that most firewalls don't proxy, it seems way too many places are allowing TCP straight out to any port, so long as it originates inside (certainly the "NAT is a firewall crowd.") How many people routinely block TCP/6667, or non-allowed applications? How many of you who don't block it do regular reports on connections initiated inside to external servers that aren't on port 80, 443, etc?
Two words: Preaching. Choir. :) That said, IMHO, you should be grateful for all the sites that allow all outbound. Firewalling is an arms race. If most sites blocked default outbound, bot/zombie authors would escalate the race by doing something like tunneling via https or some other service that was still allowed. - Morty _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? M. Dodge Mumford (Feb 02)
- Re: Botnets, IRC servers and firewalls? Gwendolynn ferch Elydyr (Feb 02)
- Re: Botnets, IRC servers and firewalls? Barney Wolff (Feb 02)
- Re: Botnets, IRC servers and firewalls? Luca Berra (Feb 02)
- Re: Botnets, IRC servers and firewalls? Victor B. Williams (Feb 02)
- Re: Botnets, IRC servers and firewalls? Mordechai T. Abzug (Feb 02)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? Marcus J Ranum (Feb 02)
- Re: Botnets, IRC servers and firewalls? Mordechai T. Abzug (Feb 02)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 02)
- Re: Botnets, IRC servers and firewalls? Gadi Evron (Feb 03)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 03)
- Re: Botnets, IRC servers and firewalls? R. DuFresne (Feb 03)
- Message not available
- Re: Botnets, IRC servers and firewalls? Marcus J. Ranum (Feb 04)
- Re: Botnets, IRC servers and firewalls? Paul Robertson (Feb 04)
- Re: Botnets, IRC servers and firewalls? Marcus J. Ranum (Feb 04)
- Re: Botnets, IRC servers and firewalls? M. Dodge Mumford (Feb 02)