From owner-freebsd-security@FreeBSD.ORG Fri Mar 21 19:20:44 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 68C8C2D0 for ; Fri, 21 Mar 2014 19:20:44 +0000 (UTC) Received: from outgoing.tristatelogic.com (segfault.tristatelogic.com [69.62.255.118]) by mx1.freebsd.org (Postfix) with ESMTP id 4915F6C2 for ; Fri, 21 Mar 2014 19:20:43 +0000 (UTC) Received: from segfault-nmh-helo.tristatelogic.com (localhost [127.0.0.1]) by segfault.tristatelogic.com (Postfix) with ESMTP id 0C2B53AD93 for ; Fri, 21 Mar 2014 12:20:37 -0700 (PDT) From: "Ronald F. Guilmette" cc: "freebsd-security@freebsd.org" Subject: Re: NTP security hole CVE-2013-5211? In-Reply-To: Date: Fri, 21 Mar 2014 12:20:37 -0700 Message-ID: <51381.1395429637@server1.tristatelogic.com> X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Mar 2014 19:20:44 -0000 In message , Remko Lodder wrote: >Reading the mails from this thread leads me to believe that there is no >stateful firewall concept in place? I am not the poster to whom you were responding (info@rit.lt), however speaking only for myself I will confess that yes, in my case at least, although I have used ipfw for many years, I have never (until now) found any compelling need to either understand or make use of any of ipfw's stateful capabilities. >In my believing it is so that if you do not filter traffic, you are >making a deliberate choice to let everyone smack your service(s). I personally *do* most certainly filter traffic, and have done, since I first connected *any* machine of mine to the Internet. I can assure yoy that I never made any deliberate choice to let everyone smack me around. Nontheless, that clearly did happen, eventually, when evil-doers decided, relatively recently, to use & abuse me as an NTP reflector, but my participation in this was not in any sense deliberate on my part, and arose strictly out of ignorance, for which I am suitably humbled and apologetic. Regards, rfg