Andrew Brennan on Thu, 28 Dec 2000 13:18:46 -0500


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] IPChains


I'm not sure I can help with the ipchains setup, but I'd be careful about
being too aggressive in squelching AIM.  AOL made that application robust
in a most annoying manner.  If it can't go out on it's normal ports, they
rigged it to use other ports and proxy ... http proxy, etc.

That would be bad enough, but I've tripped over AIM activity while trying
to track down rogue DNS servers ... so attempting to block AIM might mean
you accidentally break your connections to your secondary DNS servers.

It's admirable that it works in a hostile environment ... but still quite
sleazy programming, IMHO.

andrew.

On Thu, 28 Dec 2000, Inkdog.com Staff wrote:

> Again... I am tryin to deny service to all non basic ports.. (AOL IM.. ICQ
> stuff like that.. or enable it on a port by port basis... instead of the
> whole range being open)
> 
> Also... if someone know how to reset the ipchains rule set without me having
> to reboot the machine.. that would be helpful.
> 
> If ya need more details let me know.. thanks and I hope everyone is having a
> SAFE and fun holiday season
> 
> Anthony
> 



______________________________________________________________________
Philadelphia Linux Users Group       -      http://www.phillylinux.org
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
General Discussion  -  http://lists.phillylinux.org/mail/listinfo/plug