OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Incoming mail.

From: aklist (aklistenigmedia.com)
Date: Sun May 25 2003 - 07:10:24 CDT


> > > Firewall them
> > > This won't cut traffic costs, though
> >
> > Why not? The initial SYN packet to open a SMTP conversation would be
much
> > smaller than I whole conversation to reject them won't it?
>
> Yes, it would be smaller. But if the sending side then simply barrages
> the site with SYS packets, quite a lot of traffic will happen anyway.
>
and if your bandwidth is suffering, then maybe someone upstream from your
pipe could firewall the traffic for you (if you're on a T-3 then you prolly
don't need to worry about the traffic, just the exploit attempts themselves,
in which case you're back to a local firewall).