Re: (PM) Is ComOS affected by a land.c attack ?

Jake Messinger (jake@ams.com)
Fri, 21 Nov 1997 23:23:32 -0600 (CST)

On Fri, 21 Nov 1997, Russ Hughes wrote:

> Good deal. I would really be nice to be able to set a filter to deny my
> dial-in users from sending packets out that do not come from the ip
> address they we assigned. I don't see a way to do this with the pm

Hrm, isnt it safe enough to just deny packets that have source addresses
NOT from the class C that your dial-ups or in? Otherwise youd have to have
some way to dynamically apply each specific filter to whatever PORT the
user hacked in I mean dialed in on. COuld radius or choicenet handle this?

> My router is set to deny sending out ip's that are not ours, but it still
> lets 'em mess with my other users.

Ah so you ARE blocking it at the group level.. so they can only crash each
other.

~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~
Jake Messinger 713-772-6690 jake@ams.com
Advanced Medical Systems, Inc. jake@uh.edu
8300 Bissonnet #400 fax: 713-774-3498
Houston, Texas 77074 http://www.ams.com/~jake
~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.