From: Thomas Kuiper <tkuiper-netfilter@inxsoft.net>
To: Cedric Blancher <blancher@cartel-securite.fr>
Cc: netfilter@lists.netfilter.org
Subject: Re: about dettecting different TTL value
Date: Wed, 03 May 2006 13:53:16 +0800 [thread overview]
Message-ID: <4458454C.9080705@inxsoft.net> (raw)
In-Reply-To: <1146634258.4841.19.camel@anduril.intranet.cartel-securite.net>
Hello Cedric,
Cedric Blancher wrote:
> Le mercredi 03 mai 2006 à 13:18 +0800, Thomas Kuiper a écrit :
>
>>I think you want to filter with ebtables (like some cable ISP's do) based on
>>the mac address. ttl is not good for that.
>
>
> 1. You can spoof MAC address, there's no big deal about it, even on
> Windows. Most soho routers have a "MAC cloning" functionnality that
> exactly does this.
You can spoof anything. :-) I just wanted to point out that mac filtering is
definetly better than being based on ttl.
> 2. ISP only sees router's MAC address, may be 1 or 20 hosts behind it.
ISP's that filter are bad and ethernet isn't really designed to be secure
for that. But thats wasn't question here. Whats your solution?
Thomas
next prev parent reply other threads:[~2006-05-03 5:53 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-05-03 4:41 about dettecting different TTL value isp
2006-05-03 5:18 ` Thomas Kuiper
2006-05-03 5:30 ` Cedric Blancher
2006-05-03 5:53 ` Thomas Kuiper [this message]
2006-05-03 7:32 ` Cedric Blancher
2006-05-03 7:50 ` Thomas Kuiper
2006-05-03 8:12 ` Cedric Blancher
2006-05-03 5:23 ` Cedric Blancher
-- strict thread matches above, loose matches on Subject: below --
2006-04-24 4:36 isp
2006-04-24 5:15 ` Bob Sully
2006-04-24 9:44 ` Curby
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4458454C.9080705@inxsoft.net \
--to=tkuiper-netfilter@inxsoft.net \
--cc=blancher@cartel-securite.fr \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.