Re: CAN-2004-1137

Blizbor <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
Hi,

>>
>>Secondly would 'iptables -A INPUT -p IGMP -j REJECT' protect my machine 
>>    
>>
>>from remote attacks ?.
>  
>
Theoretically - yes. But practically - no. Why ?
Main idea is: do not allow any explictly necessary traffic. In my 
opinion as necessary
you can count protocols tcp, udp and icmp. Other upon request or after 
detecting that
somebody is trying to use them. Especially AH and ESP. "All other" 
protocols are used
very rare and mainy by the network infrastructure.
Conclusion is: why allow "all other" traffic if all infrastructure is 
yours and you know that
none of the other protocols are in use ?
So my answer is - no, because you are closing one hole after their 
exploitation. All other holes
are still widely opened. This cant be called "*wall" ;).

Regards,
Blizbor
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.