Security Incidents mailing list archives

Re: Port 113 requests?


From: Alexander Bochmann <securityfocus-incidents () freinet de>
Date: Fri, 7 Dec 2001 11:42:35 +0100

...on Thu, Dec 06, 2001 at 01:51:33PM -0700, Slighter, Tim wrote:

you really should try and specify that the rule "drops" instead of reject so
that the potential intruder is not provided with any information about their
attempted connection.

...except that Ryan Russell just explained why this is a 
bad idea (at least if you want to send mail from that machine).

Alex.


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: