Subject: Re: Preventative security features?
To: Dmitri Nikulin <setagllib@optusnet.com.au>
From: David Maxwell <david@crlf.net>
List: tech-security
Date: 11/14/2004 00:57:27
On Sun, 14 Nov 2004, Dmitri Nikulin wrote:
> > NetBSD's method was given high praise.
> 
> Weird, maybe nmap's algorithms just aren't right for this kind of thing. 

I'm not sure I follow you - in the last 24 hours, you posted nmap output
showing NetBSD as being rated with the highest category of sequence
number patterning that nmap has.

> Okay, features that still make sense after all discussion:
> 
> -Blackholing (even if only to save packet filtering efforts)

Do you mean something other than this?

http://mail-index.netbsd.org/netbsd-help/2002/12/27/0021.html

> -User/pid walling (so is this actually PR'd by someone else already?)

Yes, I think that's a worthwhile option to have available. 

> -TTY snooping

That's a curiousity for me, but I'm not convinced it's a critical
feature.

-- 
David Maxwell, david@vex.net|david@maxwell.net --> From a real request to a
helpdesk "Can you please open the following ports in the firewall: 1024-90000"
						- Anonymous to protect the guilty