- ENET.SYSOP -------------- < Пред. | След. > -- < @ > -- < Сообщ. > -- < Эхи > --
 Nп/п : 83 из 100
 От   : Michiel van der Vlist               2:280/5555        07 сен 26 22:01:18
 К    : Alexey Fayans                                         07 сен 26 23:50:01
 Тема : :)
----------------------------------------------------------------------------------
                                                                                 
@TID: FMail-W32 2.3.0.1-B20240319
@RFC-X-No-Archive: Yes
@TZUTC: 0200
@CHRS: CP850 2
@MSGID: 2:280/5555 6a9f1b8e
@REPLY: 2:5030/1997@fidonet 6a9ec3db
Hello Alexey,

On 07 Sep 26 16:57, you wrote to me:

 AF> Hello Michiel!

 AF> On Mon, 07 Sep 2026 15:22 +0200, you wrote to me:

 AF>>> Still, if I wanted to spam someone with responses to PING, I
 AF>>> could use such "vulnerability".

 MV>> And the gain of such an action would be?

 AF> Would you ask the same question to a security audit of your company
 AF> network infrastructure or something like that?

1) You`r not answering the question.
2) Knowing the motives of the attacker is usefull when designing a defence.

 When a potential vulnerability arises one should always ask the
following questions:

1) What has the potential attacker to gian?
2) What have the attacked to loose?
3) Is the proposed defence effective
4) How does the proposed defence interfere with normal operation?

 My toilet hs little defince against unauthorised use? Of course I
can take measures to make unauthorised use difficult or maybe even
impossible. I can put locks on the door, even more than one lock. Two Factor
Authorisation. But the effect will be tha I mainly make it moe difficult for
myself. It os just not worth doing all that just to prevent occasional
unaithorised use.

 The same goes for PING over unsecure links. It isn`t really a
vulnerabilty. Nothing much will happen if someone triggers a ping or a series of
pings from a spoofed source. Plus that only using ping via secure links
doesn`t make it impossible. And it interferes with ping being a usefull
tool.

 Look, I once had a mail bomb. VIA A SECURE LINK. The secure link
did not protect me. OTIH, I have had PING anabled for decades.
Including vis unsecure links. Never had a problem.

 AF> Someone may want to do that just because they can. If there is an
 AF> exploitable vulnerability, it will be exploited some day.

 There is nothing to "exploit". There is no problem with PING over
unsecure links. PING is usefull to explore the routing. Secure or unsecure.
It does jsut that. Don`t fix what aint broke.

Cheers, Michiel

--- GoldED+/W32-MINGW 1.1.5-b20260904
 * Origin: http://www.vlist.eu (2:280/5555)
SEEN-BY: 30/0 201/0 203/0 221/0 1 6 242 230/0
250/1 263/1 275/100 280/464 5003
SEEN-BY: 280/5555 292/789 854 8125 301/1 310/31
320/219 331/51 335/364 341/66
SEEN-BY: 410/9 421/790 423/81 455/19 460/58 463/68
467/70 469/122 712/848
SEEN-BY: 5001/100 5015/46 5020/290 545 715 921
1042 1146 2992 5452 8912 9696
SEEN-BY: 5022/2 5023/24 5030/1081 1997 5034/13
5051/44 5053/58 5055/73 5057/19
SEEN-BY: 5061/15 5075/35 128 6035/3 6090/1
@PATH: 280/5555 221/1 292/854 5020/715



   GoldED+ VK   │                                                 │   09:55:30    
                                                                                
В этой области больше нет сообщений.

Остаться здесь
Перейти к списку сообщений
Перейти к списку эх