Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] RE: Example firewall script (iptables)

Subject: Re: [Full-disclosure] RE: Example firewall script (iptables)
Date: Tue, 30 Aug 2005 10:01:59 -0400
On Tue, 30 Aug 2005 08:41:20 BST, =?iso-8859-1?Q?Bernardo_Mart=EDn?= said:
In my first email i requested about bad example firewall script, in later
mail i said that this script was to learn more so the scene isn't important
because i'm loking for bad script in any scene

The scenario is *very* important - the firewall rules that I have on my
laptop are demonstrably correct *for this usage*.  However, they are also
*incorrect* for other laptops, even others running Fedora Core 4 - of some
60 lines of rules, fully 3/4 of them are dealing with local oddities of
our network and what I do (for instance, there's a ruleset that does nothing
effective except make sure that iptables doesn't hit a '-j LOG' for a
retransmitted FIN+ACK for a just-torn-down connection to our mail server
that's no longer in the conntrack cache, so it doesn't show up in a feed
to our DSHield server).

And of course, it bears almost *no* relationship to what the firewall
rules look like for our Oracle servers - running my firewall rules on
the Oracle boxes would be a "bad script", as would running the Oracle
rulesets on my laptop.

Attachment: pgpTZaUtpe8Cp.pgp
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
<Prev in Thread] Current Thread [Next in Thread>