From owner-freebsd-security@FreeBSD.ORG Mon Oct 27 00:06:57 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 221AE16A4B3 for ; Mon, 27 Oct 2003 00:06:57 -0800 (PST) Received: from irc.dagupan.com (irc.dagupan.com [202.91.161.246]) by mx1.FreeBSD.org (Postfix) with ESMTP id F372743F85 for ; Mon, 27 Oct 2003 00:06:55 -0800 (PST) (envelope-from francisv-sender-21ebc3@irc.dagupan.com) Received: by irc.dagupan.com (Postfix, from userid 1022) id AB1B11DEBF8; Mon, 27 Oct 2003 16:06:50 +0800 (PHT) Received: from irc.dagupan.com (localhost [127.0.0.1]) by irc.dagupan.com (Postfix) with ESMTP id A9D2D1DEBE2 for ; Mon, 27 Oct 2003 16:06:49 +0800 (PHT) Received: from hopper (hopper.dagupan.com [202.91.161.143]) by irc.dagupan.com (tmda-ofmipd) with ESMTP; Mon, 27 Oct 2003 16:06:47 +0800 (PHT) To: Date: Mon, 27 Oct 2003 16:06:44 +0800 X-Mailer: Microsoft Office Outlook, Build 11.0.5329 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Thread-Index: AcOcYNnjE/Gm3ZmZSza98OT8fOug3wAACaOQ In-Reply-To: <20031027080240.GA9552@rot13.obsecurity.org> From: "Francis A. Vidal" Message-ID: <1067242009.66521.TMDA@irc.dagupan.com> X-Delivery-Agent: TMDA/0.80 (Determine) X-Spam-Status: No, hits=1.8 required=5.5 tests=BAYES_30,EMAIL_ATTRIBUTION,FORGED_MUA_OUTLOOK, FROM_HAS_MIXED_NUMS,IN_REP_TO,MISSING_OUTLOOK_NAME, QUOTED_EMAIL_TEXT,REPLY_WITH_QUOTES version=2.55 X-Spam-Level: * X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp) X-Sanitizer: Secured by Bitstop Network Services MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Subject: RE: Best way to filter "Nachi pings"? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: "Francis A. Vidal" List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Oct 2003 08:06:57 -0000 Wouldn't it break stuff like traceroute? -----Original Message----- From: Kris Kennaway [mailto:kris@obsecurity.org] Sent: Monday, October 27, 2003 4:03 PM To: Brett Glass Cc: security@freebsd.org Subject: Re: Best way to filter "Nachi pings"? On Mon, Oct 27, 2003 at 12:31:46AM -0700, Brett Glass wrote: > We're being ping-flooded by the Nachi worm, which probes subnets for > systems to attack by sending 92-byte ping packets. Unfortunately, > IPFW doesn't seem to have the ability to filter packets by length. > Assuming that I stick with IPFW, what's the best way to stem the > tide? Block all ping packets? Most security-conscious admins do this anyway. Kris