Extracted from the mind of Rhett R. Rodewald;


>Boffo mistake -- Ash's mods do work if applied correctly -- I thought he was
>using the "/" to seperate S-Port and D-Port, didn't realize that was the
>syntax for specifing a range.  (Noticed that after re-reading the docs...wow)

>Anyway, is there a way to make this work without opening up _all_ the ports
>from 5000 to 65555???

>Thanks again.

That's a good question. For Be I have to have 48000 to 65535 open. On the
other hand, as I understand it, If there is no program on the lan port side of
the firewall to do something with the incoming packet, nothing will happen to
any of the machines on the lan.

In this instance I suppose some one could trap the dns lookup packet and then
send back a fake IP address. That would then send the requesting program off
to the site chosen by the attacker. Which might be a problem.

Holger, I presume  the tcp auto setting allows only known (telnet or ftp say)
ports open to the internet?




                         -ash
                         for assistance dial MYCROFTXXX

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to