Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Active response... some thoughts.

From: Frank Knobbe <fknobbe(at)knobbeits.com>
Date: Wed Jan 29 2003 - 12:08:35 EST

On Mon, 2003-01-27 at 19:26, Kohlenberg, Toby wrote:

> Actually, TCP resets don't work in many cases- for instance any

In regards to firewall/router reconfig:
Yeah, the damage is done and reconfiguring firewalls don't help 'prevent' that attack, but they can help 'contain' that attack. For example, the firewall can be reconfigured to deny any traffic to and from that attacked device. While in this worm scenario it only prevents the infected host from flooding the Internet, and perhaps internal network, it doesn't prevent other infected hosts on the local segment from flooding out (unless your IDS/firewall tandem is configured in a smart way1), it does work very well on normal backdoor and bo attacks. Even in this scenario the host gets compromised, but the connection to the attacker is then cut off by the firewall and the rooted system is contained through firewall rules.

Regards,
Frank

[1] Smart way could be denying all packets of the same service crossing the firewall. That would prevent other, locally infected, hosts from flooding out.

Received on Wed Jan 29 12:21:58 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:07 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library