[1407] in bugtraq

home help back first fref pref prev next nref lref last post

Re: All.Net's security testing service

daemon@ATHENA.MIT.EDU (Melvin Klassen)
Wed Apr 5 15:40:43 1995

Date:         Wed, 05 Apr 95 10:00:00 PDT
From: Melvin Klassen <KLASSEN@UVVM.UVIC.CA>
To: bugtraq@fc.net

On Wed, 5 Apr 07:07:59 -0500 (EST) Paul Ferguson <paul@hawksbill.sprintmrn.com>
wrote:
> jdwilson@gold.chem.hawaii.edu (NetSurfer) wrote:
>> Does it work in the case of a user dialing in for PPP,
>> and then connecting to ALL.NET ?
>No. It uses reverse domain mapping (gethostbyaddr)
>to direct its vulnerability testing.

If the user is running LINUX, and using PPP to connect,
and the IP-address assigned for the session is fully-registered in the DNS,
then it would be an effective test of the security on the user's machine.

If the user is running some lesser SLIP/PPP package, then what's the point?

home help back first fref pref prev next nref lref last post