Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Ping vs www server
- Date: Sat, 19 Apr 2008 18:28:40 +0900
- From: "Josh Glover" <jmglov@example.com>
- Subject: Re: [tlug] Ping vs www server
- References: <47FE430E.3050608@imaginatorium.org> <20080417054309.GB428@lucky.cynic.net> <d8fcc0800804170305w10e06c1exf449d971a6f1c390@mail.gmail.com> <20080417233520.GB7858@pragmatic.cynic.net> <d8fcc0800804171949x15a2c2fdy82c49eb36835e646@mail.gmail.com> <ed10ee420804172136n6b169526rcf9ff7fdae4b6925@mail.gmail.com> <d8fcc0800804172309s76366adfi8bbc527a57fd54f5@mail.gmail.com> <87d4ometti.fsf@uwakimon.sk.tsukuba.ac.jp> <d8fcc0800804181504q33165ee6i3a01ea4b7dd5c1d@mail.gmail.com> <87abjqejwj.fsf@uwakimon.sk.tsukuba.ac.jp>
On 19/04/2008, Stephen J. Turnbull <stephen@example.com> wrote: > Josh Glover writes: > > > 2. Public servers should drop echo message types (0, IIRC) on the > > floor while dealing with the rest of ICMP > > I don't get this. Public servers can be pinged via TCP on at least > one port by definition. "Echo" is a tiny part of the stack, and it's > way low (technically, ICMP is encapsulated in IP same as UDP or TCP, > but considered to be part of IP rather than a higher level, see RFC > 1122). If you don't trust this part of your stack, what can you > trust? Again, I'm operating on the basic principle of security that says turn off *everything* you don't need. And I'm still not entirely convinced by your standards compliance argument; lots of network hardware no longer uses ICMP for flow control and routing, so new standards have and will emerge that are a little more robust that ICMP has proven. I mean, we basically need a new Internet, one built on protocols and standards with security baked in from the beginning rather than slathered on top. I may be wrong in my stance; but my call is to protect my network at any cost. Call me a bad citizen, but good fences make good neighbours, or some such. -- Cheers, Josh
- Follow-Ups:
- Re: [tlug] Ping vs www server
- From: Stephen J. Turnbull
- References:
- [tlug] Ping vs www server
- From: Brian Chandler
- Re: [tlug] Ping vs www server
- From: Curt Sampson
- Re: [tlug] Ping vs www server
- From: Josh Glover
- Re: [tlug] Ping vs www server
- From: Curt Sampson
- Re: [tlug] Ping vs www server
- From: Josh Glover
- Re: [tlug] Ping vs www server
- From: SL Baur
- Re: [tlug] Ping vs www server
- From: Josh Glover
- Re: [tlug] Ping vs www server
- From: Stephen J. Turnbull
- Re: [tlug] Ping vs www server
- From: Josh Glover
- Re: [tlug] Ping vs www server
- From: Stephen J. Turnbull
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Contest - Name that Linux distro!
- Next by Date: Re: [tlug] Contest - Name that Linux distro!
- Previous by thread: Re: [tlug] Ping vs www server
- Next by thread: Re: [tlug] Ping vs www server
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links