gill enscribed thusly:


> Good point, but you wouldn't be running anything else on the firewall box
> anyway, right?

        Uh...  I think that's part of the problem with NT.  At what point
are you SURE you are not running anything else on that firewall.  That
plus the fact that they have only RECENTLY (SP5) given us the ablility
to disable source-routing in the tcp/ip stack.  Prior to that, it was
enabled with no way to disable it.  How many were aware of that and how
many are confident that there aren't any other ticking timebombs buried
in that stack somewhere?

> --gill

> ->  A customer of mine uses Microsoft DNS as internal DNS Servers. Heavy
> ->  Compaq Systems, NT Server 4.0, SP4 and a few hotfixes. If I run
> ->  "nmap -sS"
> ->  against these boxes on one of them the DNS Server crashes. Not so on an
> ->  other one.

> ->  Both boxes were installed the same way, the same CDs, the same
> ->  patches by
> ->  the same MCSE (Which really knows what he does).

> ->  Now you install firewall software on them. Will it work, will
> ->  it not work,
> ->  ....?

> ->  have fun ...

        Mike
-- 
 Michael H. Warfield    |  (770) 985-6132   |  [EMAIL PROTECTED]
  (The Mad Wizard)      |  (770) 925-8248   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to