On Tue, Apr 04, 2000 at 10:10:12AM +1000, [EMAIL PROTECTED] wrote:
> Are we actually talking about methods to illegally use the optus@home
> service
> my means of deception to fool port scanners so that servers may be used?
Not at all. I was pointing out a method of securing a machine to prevent
external access to any services that may be running for use within your
local network. Note that the rules I posted blocked *all* incoming
connection requests, hence a machine configured with those rules could not
act as a server to the outside world.
My main concern was that there seemed to be a lot of people connecting
machines to the net without taking any precautions to secure that machine
against attack from outside. Being a regular target of port scans, and
even one DoS attempt, I'm acutely aware of the security risk of connecting
to the big wide world.
Of course, it's not difficult to extend the firewall rules to block just
Optus's port scans, but that's merely an indication that their method of
detecting servers is fatally flawed. Port scanning by itself can be
nothing more than an indication that the machine *may* be providing a
service accessible by the outside world. It is not a definitive test for
the presence of an externally-accessible server.
> If so, What are the legal ramifications to SLUG?
None of us are actively suggesting that people violate their AUP. If you
do violate it, then you deserve to lose your account. Whether or not you
like it, you did agree to it, and therefore you're legally and morally
bound to adhere to it.
Cheers,
John
--
whois [EMAIL PROTECTED]
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text