[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: firewall for a client




--- "Víctor A. Ramos" <itchysoft@yahoo.es> wrote:

On Tue, 2004-12-07 at 00:55 +0100, Ansgar -59cobalt- Wiechers wrote:
> On 2004-12-06 Víctor A. Ramos wrote:
> > On Mon, 2004-12-06 at 18:30 +0100, Ansgar -59cobalt- Wiechers wrote:
> >> On 2004-12-06 Victor A. Ramos wrote:
> >>> My own computer connected to the Internet is a link which can be
> >>> attacked... that!s the part of the network that I pretend to
> >>> protect.
> >> > >> Why do you believe that you need protection for something which is
> >> not there at all? You wrote that you don't have any service bound
to
> >> the external interface. If that's true, then there's nothing that
> >> possibly could be attacked.
> >> > >> Of course, your uplink could be flooded. However, a packet filter
> >> won't protect you from that kind of attack.
> > > > Well... I suppose that you're kidding me... > > No.

Thanks

> > > because there is no true in "you don't need firewalls, because
you're
> > not running any server on your PC"...
> > Then please enlighten me, because I cannot see any wrong in this for
> single hosts. Tell me, *how* is someone supposed to attack a computer
> that doesn't provide services.

One thing is that I don't want to provide any service... and other very
different is that I have programs which open ports... (i.e. mldonkey)
and this ports it could be attacked... that's what I want to prevent.
Keep inmind that p2p push requests requier that service to be open.
Failure to allow connections will cut down the servelts you can download
from.  Also keep inmind that you can still get malicious push requests,
search requests, and outgoing push connections.  So I don't see why you
would run any p2p servlet and not allow incomming connections, especialy
node connections.

> > Even I know that, dude! > > AFAICS you know wrong.

DYSWIM? ;)

Regards
--
Víctor A. Ramos <itchysoft_AT_yahoo_DOT_es>

(o_ Debian GNU/Linux .'''`. //\ Registered User : :' :
   V_/_     #315167       `. `'
` Jabber ID <vramos_AT_jabber_DOT_org>


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact
listmaster@lists.debian.org





		
__________________________________
Do you Yahoo!?
Take Yahoo! Mail with you! Get it on your mobile phone.
http://mobile.yahoo.com/maildemo




Reply to: