Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Removing ping/icmp from a network |
|---|---|
| Date: | Thu, 27 Mar 2008 13:09:27 -0400 |
On Thu, Mar 27, 2008 at 12:25 PM, Jason <securitux@gmail.com> wrote: *snip*
The idea is to limit your Internet footprint to make it as difficult as possible for an attacker. There is no need for a web server to respond to ping from the Internet for example.
It is very critical that your web server responds to ICMP on the Internet. If you go out of the way and ignore essential protocols for IP over a public network, you're just going to create a headache for all of us. Without ICMP, it is very difficult for us to determine where a problem exists when our clients complain about slow load times or inaccessibility to your website. No ICMP means no basic trace routing, no basic latency checks, and no basic error reporting. So even if the problem is somewhere in our infrastructure that limits or prevents access to your site, you're going to get the blame and bad reputation of an unstable server. If it doesn't respond to ping, and can't be traced, its not our fault that our client can't access your site, it's yours. -- Mark Owen
| Previous by Date: | RE: Looking For Security Metrics, David Gillett |
|---|---|
| Next by Date: | Re: File sharing with Bittorrent: what possible security threads?, postmaster |
| Previous by Thread: | Re: Removing ping/icmp from a network, Jason |
| Next by Thread: | R: Removing ping/icmp from a network, Vega - Brunello Ivan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |