Re: SSH brute forcers

Ken Connelly <[email protected]> Wed, 01 Jun 2005 20:05:46 -0500
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Merton Campbell Crockett wrote:

>Everyone has ingress security policies and filters but it seems precious 
>few have corresponding egress security policies and filters.
>
>If you are not permitting CIDR blocks listed in RFC3330 into your network, 
>it would be reasonable not to permit packets from or to those CIDR blocks 
>to exit from your network.  Using Cisco IOS access lists, it only takes 15 
>statements to filter out RFC3330 CIDR blocks and another 24 to filter out 
>CIDR blocks that have not yet been assigned by IANA.
>  
>
IMHO, a better egress filter is to allow only your internal public 
netblock(s) to exit.

- ken
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions