Dear zonelabs.
Jul. 9th, 2008 05:57 pmFIX YOUR FUCKING FIREWALL.
how about this instead
Dear Users,
Stop using an OS that requires a firewall.
either way
no love
taiki
how about this instead
Dear Users,
Stop using an OS that requires a firewall.
either way
no love
no subject
Date: 2008-07-10 12:59 am (UTC)no subject
Date: 2008-07-10 01:41 am (UTC)no subject
Date: 2008-07-10 01:48 am (UTC)no subject
Date: 2008-07-10 02:47 am (UTC)I'll post again after I do some tcpdumping.
no subject
Date: 2008-07-10 03:35 am (UTC)no subject
Date: 2008-07-10 02:48 pm (UTC)no subject
Date: 2008-07-10 10:39 pm (UTC)no subject
Date: 2008-07-11 07:59 am (UTC)Shouldn't a firewall just deny/allow traffic to preset ports or to detect suspicious activity?
no subject
Date: 2008-07-10 05:29 am (UTC)Firewalls shouldn't hose major Windows DLLs either.
no subject
Date: 2008-07-10 02:54 pm (UTC)no subject
Date: 2008-07-10 01:56 am (UTC)I run active firewalls on my Linux, OS X and Windows boxes.
no subject
Date: 2008-07-10 02:54 am (UTC)Until 2 years ago I didn't bother with firewalls if the only open port was 22. With all the SSH dictionary attacks I see today I tend to set people up with fail2ban which uses iptables to lock out hosts with try that.
no subject
Date: 2008-07-10 03:54 am (UTC)*blink*
I think that may be the answer to a problem I had, actually...
no subject
Date: 2008-07-10 03:56 am (UTC)BTW this was also the easy way to patch boxes infected with that one worm that would crash the RPC portmapper and trigger the 60 second countdown of doom :)
no subject
Date: 2008-07-10 02:55 pm (UTC)Oh, wait, right, Windows. You don't need to do that. This is not the functionality you are looking for.
no subject
Date: 2008-07-10 03:02 pm (UTC)I also wouldn't put in "if running services". Assuming a simple "incoming only" firewall, some malicious bit of software could start listening and the firewall would block things from being able to connect to it, so it is useful even if not running anything. Contrarily, if I have SSH open to the world, and the firewall lets everything on 22 through, then the firewall does very little.
I use it to reinforce rules I already have. So, if SSH is set via hosts.allow and hosts.deny to wrap to the local subnet, my firewall rules are the same. Thus, if either of them fails, the other will hopefully not. Defense in depth and all that.
Right now I have the firewall blocking incoming stuff only. I need to set it up to monitor and block unauthorized outgoing too...
no subject
Date: 2008-07-10 02:32 am (UTC)no subject
Date: 2008-07-10 05:44 am (UTC)no subject
Date: 2008-07-10 02:21 pm (UTC)no subject
Date: 2008-07-10 03:53 am (UTC)no subject
Date: 2008-07-10 04:33 am (UTC)But i do agree with donnaidh_sidhe --> yay fast call resolution!
no subject
Date: 2008-07-10 06:22 am (UTC)Am so glad I switched to Fedora.
no subject
Date: 2008-07-10 09:20 am (UTC)I feel sorry for anyone who has to run an OS where major system services run exposed where outsiders can hit them.
no subject
Date: 2008-07-10 06:32 pm (UTC)