[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] installing ssh on raq2



Theodore Jones schrieb:
> 
> Hans,
> 
> Care to tell me how "they" could use Portsentry again a machine?  

i did not write that; i think that the author (forgot the name and
deleted the mail) intended not only that it could be used against you,
but that you have to know what you`re doing in a more general sense;
otherwise you could have the impression of having a secured system
(which you don`t have :-)

i could imagine several types of attacks. one could deny your access if
he knows your ip (by spoofing it) or flood your logfiles by creating an
event and then -even if he is blocked- try to connect continuously.

and, portsentry does not really prevent portscans, it makes them a bit
more difficult. if i know that you use portsentry, i use a dial-up
connection with a mass provider, write a script that scans one port, and
if it get`s blocked, it hangs up, dials again (other ip highly probable)
and checks the next one. 

so a port scan takes half an hour instead of a minute...

-- 

H. P.  Ströbel

PGP Digital Fingerprint :
58E0 6ECB 620A A689 E206 
BCA8 300F BC45 6EEC F7C3

Yes, I do. But not Yahoo.