Great Circle Associates Firewalls
(October 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Reverse and double-reverse IP address lookups as service prerequisites
From: Aydin Edguer <edguer @ alpha . CES . CWRU . Edu>
Date: Mon, 5 Oct 92 15:21:22 EDT
To: Brent @ GreatCircle . COM
In-reply-to: <9210051817 . AA11323 @ mycroft . GreatCircle . COM>; from "Brent Chapman" at Oct 5, 92 11:17 am

> I agree that it's security through obscurity, and should not be
> counted on to protect anything, BUT every little bit helps.  Why give
> folks ammunition, in the way of host names that can be used for
> "social engineering" or password attempts or anything else?  Sure,
> not making the host names trivially available doesn't solve much, but
> it's one more piece of the puzzle.

But the point is that if "I" am trying to break into "your" hosts, then
"I" don't really care about the hostname, all "I" need is the IP address.
Unless you are going to hide your IP addresses, then hiding the hostnames
seems rather pointless (except for mail).  If you do hide IP addresses then
I fully agree that hiding your hostnames is important and useful.

The point of doing a "double reverse" name lookup is security/authentication.
It helps to prevent spoofing of the nameserver by people forging PTR records
in their nameservers.  Thus I think that a "double reverse" name lookup is
under normal usage [with or without firewall] going to help cut down on
"forgeries" more than hiding only the names is going to help.

Aydin Edguer




References:
Indexed By Date Previous: Re: Filters and interfaces.
From: Amos Shapira <amoss @ cs . huji . ac . il>
Next: Re: Filters and interfaces on Cisco boxes.
From: "John B. Brown" <jbb @ flare . cs . umb . edu>
Indexed By Thread Previous: Re: Reverse and double-reverse IP address lookups as service prerequisites
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Reverse and double-reverse IP address lookups as service prerequisites
From: Brent Chapman <brent @ GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com