[12372] in bugtraq
Re: Remote DoS in Axent's Raptor 6.0
daemon@ATHENA.MIT.EDU (der Mouse)
Thu Oct 28 14:49:10 1999
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
Message-Id: <199910272025.QAA20323@Twig.Rodents.Montreal.QC.CA>
Date: Wed, 27 Oct 1999 16:25:43 -0400
Reply-To: der Mouse <mouse@RODENTS.MONTREAL.QC.CA>
From: der Mouse <mouse@RODENTS.MONTREAL.QC.CA>
X-To: BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
> OTOH, anybody who truly cares about security is blocking _all_ IP
> options at their border router, long before the packet is seen by any
> firewall.
Thereby breaking any number of useful things that can be done with
things like timestamp options.
If you really care about security, use bloody decent OSes so that you
don't flippin' *need* to block IP options, you don't *need* a firewall!
Options are there because they're useful and support valuable
facilities. Block 'em if you like, but you'll get no sympathy from
*me* when something breaks for you as a result.
der Mouse
mouse@rodents.montreal.qc.ca
7D C8 61 52 5D E7 2D 39 4E F1 31 3E E8 B3 27 4B