Security Basics mailing list archives

Re: ICMP (Ping)


From: "gregh" <chows () ozemail com au>
Date: Sun, 7 Sep 2003 22:54:19 +1000


----- Original Message ----- 
From: Tim Greer 
To: gregh 
Cc: security-basics () securityfocus com 
Sent: Sunday, September 07, 2003 10:01 AM
Subject: Re: ICMP (Ping)


On Sat, 2003-09-06 at 16:53, gregh wrote:
 
----- Original Message ----- 
From: Tim Greer
To: gregh
Cc: security-basics () securityfocus com
Sent: Saturday, September 06, 2003 5:58 AM
Subject: Re: ICMP (Ping)

On Fri, 2003-09-05 at 06:15, gregh wrote:
----- Original Message ----- 
From: Tim Greer 
To: SMiller () unimin com
Cc: security-basics () securityfocus com
Sent: Friday, September 05, 2003 8:52 AM
Subject: RE: ICMP (Ping)


Fun stuff... what some people seem to fail to understand, is
that it's
unlikely someone's going to randomly probe for IP's to just
 randomly
attack.  

Sorry but script kiddies do that all the time.


And how is that going to help?  They will randomly attack it anyway.

How it helps is that it corrects an error, quite obviously.

WTF?  Corrects an "error"?  *What* 'error'? :-)

If you cannot understand English, I am sorry I am no help. I have to admit I dont know any other language fluently.


 If someone TRULY believes that "it is unlikely someone's going to
randomly probe for IP's to just randomly attack" then they need to be
told the truth which is that script kiddies DO randomly probe and
randomly attack ALL the time.


That's actually what I said myself.


Then why ask silly questions?


 The good news is that even ZA will keep script kiddies out so long as
you haven't got a backdoor installed that bypasses it.

And that your system is secure--it's not just backdoors that are the
issue.

Secure systems are just things said by people who dont know any better. "Secure as I can make it" is truthful. "Fully 
secure systems" are just asking for trouble. They dont exist. Call them "honeypots" instead.

PS - sorry if this email looks confusing quoting style. Testing a
theory about OE's ability to send plain text to the list.

Please, please don't post in HTML/fonts.

I didnt post to the list that way. I assume you wont >2+ because of it?

Greg.

---------------------------------------------------------------------------
Captus Networks
Are you prepared for the next Sobig & Blaster?
 - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
 - Precisely Define and Implement Network Security
 - Automatically Control P2P, IM and Spam Traffic
FIND OUT NOW -  FREE Vulnerability Assessment Toolkit
http://www.captusnetworks.com/ads/42.htm
----------------------------------------------------------------------------


Current thread: