Dropping packets versus rejecting them in firewall rules
There's a reasonably popular view that having your firewall dropundesired packets instead of sending ICMP rejections is 'moresecure'. It is not; instead it is 'more annoying'.
(Technically this is not quite true; in a very limited set ofcircumstances, dropping all packets for a host can hide someinformation from attackers. The flipside is that dropping some but notall packets usually leaks information about what you're screening.)
Dropping packets is more annoying because attempted connections haveto time out before
Weekly spam summary on December 3rd, 2005
I'll lead with Hotmail's spam numbers:
- four emails accepted, and I know for sure that two of them werespam.
- 239 messages rejected because they came from non-Hotmail emailaddresses.
- 24 messages refused because their sender addresses had already hitour spamtraps.
- 10 messages refused due to their origin IP address (5 in the SBL, 4in the CBL, and one from Nigeria).
The case for banning Hotmail entirely becomes more and morecompelling. It's probably time
我在凌晨的街頭悲從中來,不是為了一己的訪問。
我想,大眾傳媒是需要藝術的,因為:
利益上(藝術始終具有某
How to do TCP keepalives in Python
TCP keepalives are do-nothing packets the TCP layer can send to see ifa connection is still alive or if the remote end has gone unreachable(due to a machine crash, a network problem, or whatever). Keepalivesare not default TCP behavior (at least not in any TCP stack thatconforms to the RFCs), so you have to specifically turn them on.(There are various reasons why this is sensible.)
In Python you can do this with the .setsockopt() socket method,using
CBL listings broken down by ISP
Chris Lewis of Nortel recently posted a breakdown of CBL listings byISP in news.admin.net-abuse.email. Here's the top ten of his listing:
375649 chinanet.cn.net130245 cnc-noc.net102931 telekom.gov.tr80936 kornet.net67721 tpnet.pl51671 dtag.de47246 rain.fr3
Iptables modules that aren't in the iptables manpage
I recently discovered that not all of the iptables extension modules are documented in the iptables manualpage, at least the versions installed on Debian Sarge or Fedora Core4; they're only documented in the netfilter.org extensions HOWTO here ,or sometimes not even there.
I care about this because this means there's interesting things I coulddo with iptables that I can't find out by reading the manpage. So for myfuture reference and anyone else's use, here's a quick summary of
關於論戰
我極其討厭蘇格拉底。當各處有聲音勸我息事寧人、對立的聲音愈來愈統一、各種跡象暗示現在不是一
WTO ? 關人鬼事呀 !
為迎接十二月世貿部長級會議在港舉行,而社會氣氛又在新聞媒體煲水下漸趨緊張。大家都在等著睇韓國農民或外地示威者如何剎人放火破壞香港,wto背後問題又好似"關人鬼事"的時候。
嘩...咁鬼悶的
Stopping brute-force ssh scans the easy way
I recently stumbled over this blog entry on a nice, easy way to stop brute force ssh scans, so it's time tospread this knowledge around.
If you've got an ssh daemon exposed to the Internet, you know aboutthe brute force ssh scans and password guessing attacks. The realproblem with them is the sheer volume, which creates log clutter (andsystem load) as they spew login failures and unknown users all overyour logs.
(If brute force ssh attacks give you security ulcers,
致歉
韓語
怎麼講
那些圍板永遠都太高
放的人搞錯了方向
本週二六點半無線新聞報導順序:世貿示威區安排惹不滿。示威區向海。有圍板與石壆。韓國農民代表感不滿, 因為他們想看到香港市民,怕圍板令市民們聽不到他們的聲