Re: (PM) Is ComOS affected by a land.c attack ?

Jake Messinger (jake@ams.com)
Sat, 22 Nov 1997 00:02:32 -0600 (CST)

On Fri, 21 Nov 1997, Warren Vanichuk wrote:

> If somebody knows of a better way, I'd be happy to hear about it. I want to
> initiate this type of filtering, as I'm just a paranoid BOFH.. ;)

Hrm, I think I figured it out. You have something that monitors the
syslogs or the accounting logs, for the address was assigned the user and
on what port, then you use pmcmd to delete any old filter for that ip
address and insert the NEW filter for that address specific to that PORT!
What do you guys think of that?

~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~
Jake Messinger 713-772-6690 jake@ams.com
Advanced Medical Systems, Inc. jake@uh.edu
8300 Bissonnet #400 fax: 713-774-3498
Houston, Texas 77074 http://www.ams.com/~jake
~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.