On 1/20/06, Eliah Kagan <[EMAIL PROTECTED]> wrote:
> > Z sends spoofed packets coming from the DNS server of X even more
> > interesting..
>
> When Sygate PRO "blackholes" a host, does it block only unsolicited
> packets (bad), or does it block *all* incoming packets from that host
> (worse)?
It b
Zoller
Sent: Friday, January 20, 2006 5:58 PM
To: full-disclosure@lists.grok.org.uk
Subject: Re[2]: [Full-disclosure] Personal firewalls.
Dear Eliah Kagan,
EK> Then Z comes along and sends a
EK> bunch of SYN packets to X, spoofed to have the source IP of Y, waits
EK> 10 minutes, and repe
> Z sends spoofed packets coming from the DNS server of X even more
> interesting..
When Sygate PRO "blackholes" a host, does it block only unsolicited
packets (bad), or does it block *all* incoming packets from that host
(worse)?
-Eliah
On 1/20/06, Thierry Zoller <[EMAIL PROTECTED]> wrote:
> De
Dear Eliah Kagan,
EK> Then Z comes along and sends a
EK> bunch of SYN packets to X, spoofed to have the source IP of Y, waits
EK> 10 minutes, and repeats ad infinitum.
Z sends spoofed packets coming from the DNS server of X even more
interesting..
--
http://secdev.zoller.lu
Thierry Zoller
Finge