Bug#583364: fail2ban: using named filter insecure

2010-06-28 Thread Nico Golde
Hi, * Yaroslav Halchenko deb...@onerussian.com [2010-06-28 12:12]: doh me -- I let your bug report stay without attention for so long. Would you think that disabling / advising-against for named filter only for UDP connections would be sufficient? IP spoofing in TCP is somewhat elaborate and

Bug#583364: fail2ban: using named filter insecure

2010-06-27 Thread Yaroslav Halchenko
doh me -- I let your bug report stay without attention for so long. Would you think that disabling / advising-against for named filter only for UDP connections would be sufficient? IP spoofing in TCP is somewhat elaborate and wider problem, so most of defensive mechanisms could be said to be weak

Bug#583364: fail2ban: using named filter insecure

2010-05-27 Thread Nico Golde
Tags: security Severity: important Package: fail2ban Hi, here's the bug report now :) For reasons outlined in: http://nion.modprobe.de/blog/archives/690-fail2ban-+-dns-fail.html the named filter should be removed from the standard Debian installation. Cheers Nico -- Nico Golde -