Great Circle Associates List-Managers
(June 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sendmail and IDENT protocol delays...
From: Chuq Von Rospach <chuqui @ plaidworks . com>
Date: Tue, 30 Jun 1998 07:52:01 -0700
To: Todd Vierling <tv @ pobox . com>, Chuq Von Rospach <chuqui @ plaidworks . com>
Cc: list-managers @ GreatCircle . COM
In-reply-to: <Pine.NEB.3.96.980624154256.238F-100000@like.duh.org>

At 12:44 PM -0700 6/24/98, Todd Vierling wrote:

> Ask the firewall admin if the firewall can be set-up to return RST instead
> of "nothing".  That response is equivalent to a "Connection refused".

I did, just for information purposes. His response was he WANTS
nothing. First, it slows down an attempt to scan through the firewall
(since everything has to time out instead of returning immediately. And
that's what started this thread... grin), and second, the less
information he gives hackers, the happier he is. And using RST instead
of a blank wall tells them something's there....

> IMHO, "mis-feature" or not, outbound IDENT should be allowed for logging
> purposes.

the general response I've gotten, frankly, is that IDENT is pretty
useless and unreliable, but I ought to run it anyway, just in case
someone finds it useful. That seems silly logic to me. I've never run
an IDENT server on a machine, and this is the first time it's come up
in any discussion, so it sure doesn't seem important. And I've talked
to a number of TCP hacks about it since this came up, and most feel
it's of limited usefulness and easy to spoof, and they think it's a
mis-feature that it's on by default in sendmail.

FWIW.

--
Chuq Von Rospach (Hockey fan? <http://www.plaidworks.com/hockey/>)
Apple Mail List Gnome (mailto:chuq@apple.com)
Plaidworks Consulting (mailto:chuqui@plaidworks.com)
<http://www.plaidworks.com/> + <http://www.lists.apple.com/>


Follow-Ups:
References:
Indexed By Date Previous: Spam on the list?
From: Mike Nolan <nolan@celery.tssi.com>
Next: Re: Spam on the list?
From: Clint Bowman <clint@ecy.wa.gov>
Indexed By Thread Previous: Re: Sendmail and IDENT protocol delays...
From: Todd Vierling <tv@pobox.com>
Next: Re: Sendmail and IDENT protocol delays...
From: Sheryl Coppenger <sheryl@seas.gwu.edu>

Google
 
Search Internet Search www.greatcircle.com