Re: How to survive in a Micro$oft environment??

From: Anton Ivanov (aivanov@eu.level3.net)
Date: Mon Feb 28 2000 - 09:04:17 EST


-----BEGIN PGP SIGNED MESSAGE-----

>
> When does it look hostile? Does a simple DNS query look hostile?

Yes. See BUGTRAQ for the latest method to use named as a flood generator.

>
> How about some poor sucker whose hardware gets hosed, and he wants to
> find out the time from someone elses "time" service? Is he hostile
> if he scans for open "time" ports?

Yes.

There is a list of publically available time servers. Most of them stratum 1 (or
2 at worst). Scanning for one instead of using a known publically available
server is at least strange ;-)

Lists are at:

http://www.eecis.udel.edu/~mills/ntp/clock1.htm
http://www.eecis.udel.edu/~mills/ntp/clock2.htm

>
> I used to use rdate every time I rebooted because of such a hardware
> problem. Best I could do was such a scan on the metalab.unc.edu subnet.
> Every few weeks they'd shut off the time server on the machine I was
> using though.

[snip]

And caldera config utility should ask before scanning after it has failed to
locate resources via DHCP. That is besides the fact that it should try BOOTPC,
bootparams, rdisc and a couple of other things as well if DHCP fails . And warn
the user of course that it is going to fire at random at everything that
moves ;-)

This is OT, inbtw ;-)

- ----------------------------------
Anton R. Ivanov
IP Engineer Level3 Communications
RIPE: ARI2-RIPE E-Mail: Anton Ivanov <aivanov@eu.level3.net>
@*** Drucker's Dicta: (No 13 of 15) ***
      Look at governmental programs for the last fifty years. Every single
      one -- except for warfare -- achieved the exact opposite of its
      announced goal.

- ----------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.0 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iQEVAwUBOLqAXylWAw/bM84zAQHaqgf/XHhhd4qCIiPFSe5RYM+aYWc/JYNWfCsy
9zLc8yp/bw5mPonxgoUTm0Wi/3quBqvNaqqdyyiRzSif8HlLg3dbirZhnb0PBmHX
HKuSBFHf7KJgGSbdIECAwxEWOWbpz+N4hfEFKg53OylEGm6ywK6z+N+DQeOaS0g+
j8haGhYXIZS6Bn0cDg70mHPc5gFQTd0J5Eh+x/a7au7CA1F1kVR3mB9oj0TLasvF
+KIy35s+urnttiCRygJY9LYpiBzxmxUJj6NUC5Sye4R/tPR1ZrA+UAYJeNYYwrS3
5JdNQZElHblQQOnZZBMOAVjLF8KHxQxUY+6SqaGZPoW4ZiptAQEsFg==
=etUo
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Tue Feb 29 2000 - 21:00:19 EST