Berkeley CSUA MOTD:Entry 22011
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2024/11/23 [General] UID:1000 Activity:popular
11/23   

2001/8/5-6 [Computer/Networking] UID:22011 Activity:very high
8/5     I've just setup a new firewall at home and I'm looking for a
        tool to test it out. Any recommendations?
        I'm also running a caching DNS server on the firewall and I'd
        like to setup a rule that allows the server to make queries
        and recieve responses but that blocks inbound queries. I can't
        seem to figure out how to do this though as my ipf fu is weak.
        Any suggestions? Thanks.
        \_ you want it so that you can run internal dns, but not have
           external machines able to query your internal dns?  Can you
           run 2 nameservers on your network then?
           \_ Not necessary to run 2 nameservers, that's overkill.  BIND
              has a directive which allows you to specify which servers
              are allowed to query it.  I'll double-check and get back to
              you.
              \_ somewhat obviously, the option you want is 'allow-query'.
                 \_ This does not seem to be a supported BIND4 directive.
                    Do you know if there is an equivalent?
                    \_ No, there is no equivalent.
           \_ The caching nameserver handles the nameservice queries for
              the internal nat'ed network. The dns for the public systems
              in the dmz are hanled by my isp.
              In BIND8 you can tell it to bind() and listen() for connections
              on selected ip's on the system system, but I'm stuck running
              BIND4 which doesn't support this feature. Thus I'm trying to
              figure out a ipf rule that will allow me to run caching dns
              while preventing '1337 h4x0r5 from trying to exploit the
              nameserver.
              \_ Why are you running BIND4?  There's no good reason to.
                 \_ Okay stuck was a bad choice of words. BIND4 for OpenBSD
                    has been audited while BIND8 has not. I just wanted that
                    extra level of protection and I wanted to avoid having
                    to install /usr/ports on the firewall in order to build
                    BIND8. Anyway it looks like I'm just going to have to
                    install BIND8. Thanks.
                    \_ Okay, let me get this straight.  You're running BIND
                       on your firewall box.  Are you INSANE?!?  If you
                       care about having a secure nameserver, don't run
                       BIND.  Run djbdns (Dan Bernstein's uber-paranoid
                       DNS server).
                       \_ OpenBSD BIND4 is audited. Its not the same as
                          stock BIND4 or BIND8. I thought about djbdns.
                          There are problems with the way that it does
                          recursive queries that break my webcache so
                          I can't use it.
                          As far as the firewall is concerned if udp 53
                          is open on my internal ip but closed on my
                          external ip, external attacks cannot exploit
                          any weaknesses in BIND. This is the level of
                          security I'm looking for. (I case this box is
                          hacked, I've got another with a similar image
                          ready to go, I can just power than one on and
                          switch over while the regular machine is being
                          reimaged from known safe media)
        \_ you could try ShieldsUp! at http://grc.com
           \_ The guy who runs this site is a freak! I don't know
                about the quality of his programs, but I would not
                want to support him.
              \_ why not?  sure, his site looks unprofessional, but you have to
                 respect someone who codes win32 apps in asm.  his denial of
                 service story is good reading too.
        \_ go to http://www.dslreports.com click on tools then port scan.
           \_ Thanks, I'll try this out.
        \_ May I reccomend nmapping your site from outside?
           \_ I've performed a TCP connect(), SYN, FIN, Xmas, NULL, and
              a UDP port scan. The only open port that was detected was
              tcp 22 (SSH) and udp 53 so most of my rules appear to be
              working. The bits I want to test are filter input and output
              packets with invalid source and destination addresses. I'm
              a nmap novice and can figure out how to do this. I suppose
              I could just write a raw packet generator, but someone must
              have already wrote one so I'm looking for recommendations.
              Thanks.
2024/11/23 [General] UID:1000 Activity:popular
11/23   

You may also be interested in these entries...
2009/11/4-17 [Computer/SW/P2P, Computer/Networking, Computer/SW/Security] UID:53495 Activity:nil
11/4    Holy cow, I got a warning from my ISP that they were notified
        by BSA/baytsp.com that I was copying music/video/software.
        Do they do port scan or something? That's a first for me.
        \_ They hang out on P2P networks and track IP addresses.  -tom
           \_ I believe they are paid by content providers to perform this
              monitoring service, so you should only run this risk with content
	...
2008/11/7-13 [Computer/Networking] UID:51876 Activity:low
11/7    Need help on http proxy. After I VPN to work, I'd like to tunnel
        all the traffic to my machine. How do I setup my machine (Linux)
        as a proxy server so that my home computers can route through it?
        I'm asking because the site we're testing on requires that we
        come from the same IP. If I use VPN, the server will reject me
        based on the fact that it's a different IP than my work Linux.
	...
2008/8/5-10 [Computer/Networking] UID:50788 Activity:nil
8/5     It looks like my company has started blocking HTTPS tunneling.
        I used to do this by tunneling SSH through the HTTP/HTTPS proxy
        server, but this seems to have stopped working. Does anyone know
        how the implementation of tunneling detection works, and whether
        there are widely available implementations? We run a bunch of MS
        stuff, so I imagine we're running an MS proxy server or something.
	...
2007/6/28-7/2 [Computer/SW/SpamAssassin] UID:47111 Activity:nil
6/28    Q: What are folks using these days for anti-spam measures?  I'm
        looking for something that integrates with my MTA (postfix) or my
        delivery agent (sieve).  Currently I'm using a crufty version of
        spamassassin wired into postfix via amavisd-new.  It's decent, but I
        don't want to be bothered with manually upgrading spamassassin or
        updating rulesets on a regular basis.  Anyone have any experience
	...
2006/10/31-11/2 [Computer/SW/OS/Windows] UID:45057 Activity:moderate
10/31   A friend of mine said he's loving Microsoft again because Bill G
        is starting to donate all of his money to charity. He's boycotting
        Google, Yahoo, and other mega companies because they're too big and
        too power and thinks they're all becoming the old Microsoft, whereas
        Microsoft has recently done a lot of good things like investing in
        education and charity. He just paid for a copy of Microsoft Windows
	...
2006/5/8 [Computer/SW/Security] UID:42976 Activity:moderate
5/8     why you are getting all that blue frog spam
        http://q.queso.com/archives/001917 - danh
        \_ While I'm not ready to call it outright bullshit, I'm skeptical:
           * Most DNS operators with a clue set TTL values to cache records
             for 24 hours to one week.  The DNS notify mechanism leaves much
             to be desired.  Thus, changing a DNS pointer is unlikely to
	...
2006/2/18-23 [Computer/Networking] UID:41923 Activity:low
2/18    My DSL modem's ip address is 192.168.0.1, my internal network
        behind my router is 10.0.0.x. Is there a way I can configure
        the router so I can access the DSL modem from my 10.0.0.x
        network directly without re-wiring? Static routes? I tried it
        but no much luck. I also tried changing my internal network to
        192.168.0.x, but still does not work. Thanks.
	...
2006/1/28-31 [Computer/Networking] UID:41585 Activity:low
1/28    Just switched to Comcast from SBC and generally happy with it.  But
        can someone please explain to me why they are constantly pumping
        ARP traffic through the network?  It seems harmless, but I'm curious
        as I didn't see it with DSL.  It's a little disconcerting to see
        constant traffic on your router, even if ARPs are harmless from
        a bandwidth perspective, and it makes the WAN send/receive light
	...
2006/1/22-24 [Computer/Networking] UID:41477 Activity:nil
1/21    I am trying to setup a small network for my girlfriend's
        mom's company.  They just bought an accounting package
        which requires windows 2003 server.  And they want internet
        access from each computer.  How should the network be setuped?
        Would it be dumb to use static IP for each computer and a
        computer as internet gateway?
	...
2005/8/29-30 [Computer/Networking] UID:39329 Activity:moderate 54%like:37400
8/29    What's the difference between a hub, a switch and a router?  Thx.
        \_ AFAIK, probably be corrected by someone:
           hub: Allows communication on a LAN with bandwith shared amongs all
                the nodes on the hub and maxing out at the max line speed.
           switch: Allows communication on a LAN with bandwith greater than
                the max line speed (point to point)
	...
2005/6/2-3 [Computer/Networking] UID:37941 Activity:moderate
6/2     I've been to many places and almost every place I go to have
        802.11b/g. However, almost all of them have protected access,
        which I presume they use because they don't want people stealing
        their bandwidth. So here is one idea I think will really
        revolutionize 802.11X... an option in the router that allows you to
        specify the percentage of unprotected bandwidth you are willing to
	...
2005/5/23-25 [Computer/Networking] UID:37799 Activity:nil
5/23    Has anyone played with carp/pfsync on OpenBSD? I have a simple
        two firewall setup, one fw running 3.6, the other running 3.7.
        Right now the 3.6 system is the "master" and everything seems
        to work properly except that I can't ping the virtual ip from
        the master system. Any ideas?
        \_ I've seen this with a lot of virtual IP/failover/load balancers.
	...
Cache (877 bytes)
www.dslreports.com
City Community Chat: 127 New York 128 San Francisco 129 Chicago 130 Los Angeles 131 Seattle 132 Washington+ 133 Austin 134 Boston 135 Detroit 136 Dallas New New New: 137 Mobile Speed Test 138 Doctor Ping Current 139 Poll: Does your provider offer free backup dial-up service? I see we already blocked a UK author (for 36 hours) trying to fly into the US from Vancouver, BC. My connection tests are failing at either the PPOE or the DNS stage. According to a VADI notification I received from Verizon 2 days ago, Base package speeds are now up to 1. I'm not an idiot (although my wife may disagree at times). Comcast 193 Town squares off versus PR machine 194 28 comments : 1186 views Posted 04-30 17:50 195 G-mail Invites on Ebay 196 42 testers auctioning off beta slots Most Discussed 197 42 comments : 1767 views Posted 04-30 15:48 198 Comcast Video Mail Beta 199 Revolution?
Cache (210 bytes)
grc.com
Gibson Research Corporation Proudly Publishes hard drive data recovery software #1 Hard Drive Data Recovery Software And the exclusive home of . More than 27,755,376 shields tested! To proceed, wait a moment .