OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Sheldon Hearn (sheldonhstarjuice.net)
Date: Fri Apr 12 2002 - 10:08:00 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Fri, 12 Apr 2002 21:07:10 +1000, Andy Farkas wrote:

    > Question: the above rule in the default /etc/hosts.allow file is *above*
    > the rules regarding sshd - does this mean that sshd is not protected
    > against forged source IP adresses?

    Given the high psuedo-random quality of modern FreeBSD's TCP ISN
    generation, do you think it's worth worrying about people spoofing SSH
    connections?

    Ciao,
    Sheldon.

    To Unsubscribe: send mail to majordomoFreeBSD.org
    with "unsubscribe freebsd-security" in the body of the message