From owner-freebsd-security Thu Sep 20 15:37:32 2001 Delivered-To: freebsd-security@freebsd.org Received: from webs1.accretive-networks.net (webs1.accretive-networks.net [207.246.154.13]) by hub.freebsd.org (Postfix) with ESMTP id 12FF637B405 for ; Thu, 20 Sep 2001 15:37:28 -0700 (PDT) Received: from localhost (davidk@localhost) by webs1.accretive-networks.net (8.11.1/8.11.3) with ESMTP id f8KLX7033945; Thu, 20 Sep 2001 14:33:07 -0700 (PDT) Date: Thu, 20 Sep 2001 14:33:07 -0700 (PDT) From: David Kirchner X-X-Sender: To: Krzysztof Zaraska Cc: Giorgos Keramidas , Dennis Mathiasen , Subject: Re: NIMDA Virus (OT) In-Reply-To: Message-ID: <20010920143246.O85958-100000@localhost> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Fri, 21 Sep 2001, Krzysztof Zaraska wrote: > Some people say that web server(s) should not be allowed to initiate any > outbound connections (and especially to port 80) not necessary for normal > operations, so if they have all servers on a separate subnet (what makes > sense) they can just prohibit outbound HTTP from that network only. So > setting up a proxy is not necessary. Me, I just prefer to patch the holes instead of hiding behind filters. ;-) To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message