[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freebsd-hackers
Subject:    Re: Could use a favor
From:       Julian Assange <proff () suburbia ! net>
Date:       1996-09-19 13:42:11
[Download RAW message or body]

> 
> I'm familiar with the theory of firewalls, but have never run
> one so I lack the experience to fully understand this. But this
> reply caught my attention.
> 
> Why is an (effectively) disabled firewall "dangerous"? Is it more
> "dangerous" or exposed to security problems than a machine that
> has been configured without a firewall at all?
> 
> David Nugent, Unique Computing Pty Ltd - Melbourne, Australia
> Voice +61-3-791-9547 Data/BBS +61-3-792-3507 3:632/348@fidonet
> davidn@blaze.net.au http://www.blaze.net.au/~davidn

The problem is that the interface may go up before you have added all
your firewall rules creating a window of opportunity for the attacker.

-- 
"Of all tyrannies a tyranny sincerely  exercised for the good of its victims  
 may be the most  oppressive.  It may be better to live under  robber barons  
 than  under  omnipotent  moral busybodies,  The robber baron's  cruelty may  
 sometimes sleep,  his cupidity may at some point be satiated; but those who  
 torment us for own good  will torment us  without end,  for they do so with 
 the approval of their own conscience."    -   C.S. Lewis, _God in the Dock_ 
+---------------------+--------------------+----------------------------------+
|Julian Assange RSO   | PO Box 2031 BARKER | Secret Analytic Guy Union        |
|proff@suburbia.net   | VIC 3122 AUSTRALIA | finger for PGP key hash ID =     |
|proff@gnu.ai.mit.edu | FAX +61-3-98199066 | 0619737CCC143F6DEA73E27378933690 |
+---------------------+--------------------+----------------------------------+

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic