From owner-freebsd-questions@FreeBSD.ORG Wed Aug 13 05:01:37 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4FB2C37B416 for ; Wed, 13 Aug 2003 05:01:35 -0700 (PDT) Received: from franky.speednet.com.au (franky.speednet.com.au [203.57.65.5]) by mx1.FreeBSD.org (Postfix) with ESMTP id D700D43F75 for ; Wed, 13 Aug 2003 05:01:33 -0700 (PDT) (envelope-from andyf@speednet.com.au) Received: from hewey.af.speednet.com.au (hewey.af.speednet.com.au [203.38.96.242])h7DC14kO041848; Wed, 13 Aug 2003 22:01:20 +1000 (EST) (envelope-from andyf@speednet.com.au) Received: from hewey.af.speednet.com.au (hewey.af.speednet.com.au [172.22.2.1])h7DC13HT092575; Wed, 13 Aug 2003 22:01:04 +1000 (EST) (envelope-from andyf@speednet.com.au) Date: Wed, 13 Aug 2003 22:01:03 +1000 (EST) From: Andy Farkas X-X-Sender: andyf@hewey.af.speednet.com.au To: Mark In-Reply-To: <200308130956.H7D9U28E022832@asarian-host.net> Message-ID: <20030813215540.T90272-100000@hewey.af.speednet.com.au> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-questions@freebsd.org Subject: Re: Restricting ICMP X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 13 Aug 2003 12:01:37 -0000 Mark wrote: > I am just not very fond of the idea of local users starting ICMP wars over > the net, using my server :) I have already had an instance where a web-user > did an excessive ping attack on one of his buddies. And, naturally, I want > to prevent that. The chmod u-s idea mentioned here, was a good idea. Except > that, prefereably, I'd like all of wheel to have access, and the rest not. > And that may be harder to implement. If your users play up, put your BOFH hat on and lart them. chmod'ing /sbin/ping is useless - users can compile their own version of ping. Make your users aware that abusing ping (and other net resources) will get them kicked and banned from your system. -- :{ andyf@speednet.com.au Andy Farkas System Administrator Speednet Communications http://www.speednet.com.au/