From: "James Mello" <james.mello@wamu.net>
To: 'Antony Stone' <Antony@Soft-Solutions.co.uk>, netfilter@lists.samba.org
Subject: RE: Question
Date: Fri, 21 Jun 2002 16:16:45 -0700 [thread overview]
Message-ID: <001c01c21979$b6b61a40$8147370a@washingtghv9lt> (raw)
In-Reply-To: <20020621231230.XKAD19225.mta07-svc.ntlworld.com@there>
> > No, but there are experimental modules that will allow you
> to enforce
> > your own rules. I've heard of some IDS or attack detection
> > capabilities being done through IP tables.
>
> What sort of modules ? I *hope* you don't mean the 'string' match ?
Yeah, I actually do mean the 'string' match :) I've got some friends who
used this to do some filtering on content on their own internet exposed
boxes to prevent stupid Nimda worm and other attacks from being
perpetrated. They *did* say it was slow, but overall it's been a pretty
effective solution for them. Note I *never* did say that you can do all
sorts of Layer 7 evaluation (or validation) like the guy said. I just
suggested this as an option to do some layer 7 filtering and content
checking...
-- Cheers
-- James
next prev parent reply other threads:[~2002-06-21 23:16 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-06-21 17:33 Question Krish Ahya
2002-06-21 17:40 ` Question Antony Stone
2002-06-21 18:31 ` Question James Mello
2002-06-21 23:12 ` Question Antony Stone
2002-06-21 23:16 ` James Mello [this message]
2002-06-21 23:26 ` Question Antony Stone
2002-06-22 2:11 ` Question Jack Bowling
2002-06-22 15:25 ` Question Stephen Frost
2002-06-22 15:42 ` Question Ramin Alidousti
2002-06-21 18:59 ` Question Nick Drage
2002-06-21 19:41 ` Question Rowan Reid
2002-06-22 0:26 ` Question Sascha Reissner
-- strict thread matches above, loose matches on Subject: below --
2003-06-12 20:41 question Sander Sneekes
2003-06-12 22:11 question George Vieira
2003-09-25 14:04 question emiliano
2005-10-27 7:55 question Marcin Giedz
2005-10-27 8:18 ` question Ruprecht Helms
2005-10-27 8:39 ` question Marcin Giedz
2005-10-27 9:09 ` question Ruprecht Helms
2005-10-27 9:28 ` question Sorin Panca
2005-10-27 9:40 ` question Marcin Giedz
2005-10-27 10:04 ` question Oskar Andreasson
2005-10-27 10:25 ` question Marcin Giedz
2005-10-27 10:37 ` question Oskar Andreasson
2005-10-27 11:18 ` question Marcin Giedz
2005-10-27 13:28 ` question Oskar Andreasson
2006-06-21 12:14 question Fabio S. Silva
2006-06-21 12:23 ` question Sietse van Zanen
2008-04-28 9:01 Question Karim Reda Fakhir
2008-04-28 10:11 ` Question Jan Engelhardt
2008-04-29 1:51 ` Question Diego Lacerda
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='001c01c21979$b6b61a40$8147370a@washingtghv9lt' \
--to=james.mello@wamu.net \
--cc=Antony@Soft-Solutions.co.uk \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox