Great Circle Associates Firewalls
(May 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Countermeasures ?
From: Jonny Llama <llama @ ra1 . randomc . com>
Date: Tue, 28 May 1996 20:30:31 -0400 (EDT)
To: nmorgan @ smtp . dgs . ca . gov (Morgan, Noel)
Cc: firewalls @ greatcircle . com
In-reply-to: <9604288332 . AA833297486 @ smtp . dgs . ca . gov> from "Morgan, Noel" at May 28, 96 08:25:18 am

> 
>      
>      Gentlepersons;
>      Just a thought, but has anyone addressed the issue of proactive 
>      countermeasures?  For example if one detects a sequential probe of one's 
>      tcp or udp ports, what would prevent one from firing back a couple of 
>      hundred thousand 1500 byte packets to the sender? (assuming adequate 
>      bandwidth)

That's just being a jerk.  Clogging up other people's pipe just because 
you're getting groped by some ueberhacker is just A Bad Idea.

>      
>      Or???
>      
>      I know some systems, like Raptor, let you send back a nag-o-gram mail 
>      message, but what about active reponses?
>      

Or Fred Cohen's patented eccentricWare(tm). :-)

>      Any thoughts or discussion?  Any sample PERL scripts or code?
>      

A better idea is just to let humans do the nasty follow up work, instead 
of allowing weekend pseudo-AI perl scripts fire off nasties based on some 
crummy heuristics.  Unfortunately, just because the bonehead admin on the 
other network didn't have time to fix last yea'rs RPC holes doesn't make 
proactive attack responses a good idea.

>      
>      Noel Morgan
>      Sr. Systems Engineer
>      AmeriData Inc.
>      Assigned to Calif. Dept. of General Services
>             Office of Information Services
> 
> 

one.one.twenty.twenty.nine.tonight.the.stars.are.shining.bright
o Herr Llama <llama @
 randomc .
 com> t "Then the chair runs right t
o http://www.randomc.com/~llama  t up to my bed and jumps in. t
o \|/ ____ \|/                   t And  I  make love  to  the t
o  @~/ ,. \~@  Just another VHDL t wooden chair. It was uncom t
o /_( \__/ )_\        hacker.    t fortable. It hurt."        t
o    \__U_/                      t      -- Yevgeny Zamyatin   t
one.one.twenty.twenty.nine.tonight.the.stars.are.shining.bright



References:
Indexed By Date Previous: Re: Re[2]: Encryption Technology
From: Bill Stout <bill . stout @ hidata . com>
Next: Re: Countermeasures ?
From: eckes <ecki @ lina . inka . de>
Indexed By Thread Previous: Countermeasures ?
From: "Morgan, Noel" <nmorgan @ smtp . dgs . ca . gov>
Next: Re: Countermeasures ?
From: eckes <ecki @ lina . inka . de>

Google
 
Search Internet Search www.greatcircle.com