Re: proxy to bypass firewall?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: proxy to bypass firewall?

From: Walter Roberson <roberson@ibd.nrc-cnrc.gc.ca>
Date: Thu Aug 04 2005 - 22:24:38 CEST

In article <W5KdnZh_zLVN-W_fRVn-oA@comcast.com>,
Charles Newman <charlesnewman1@comcast.do.not.spam.me.net> wrote:
: This also proves my point why software-based
:systems are better than hardware appliances.
:Tiny notifies me on screen instantly of any
:activity not in the ruleset, and prompts me
:to decided whether to ban or allow it in the
:future. That is something your hardware
:appliances have not learned yet. If a script kiddy
:tries to make a scan on my network, and there is
:no rule in the rulset, an alert comes up on the
:screen instantly, and then I can tell it to ban
:the activity in the future.

How fast can you click your mouse? How long can you keep that rate up?

The lowly hardware appliance guarding us intercepts approximately
four hundred thousand attempts per day (more on busy days.)
That's an average of more than 4 1/2 per second, all day and all
night.

Even if one supposed that each scan was for an average of 4 1/2 IPs
[which isn't the case -- small-scope hits are in the majority these days]
then one would still have to make a decision about every 1 second.
Every second. How long could you keep up? How's your RSI holding out?

-- 
   I was very young in those days, but I was also rather dim.
   -- Christopher Priest
Received on Thu Sep 29 20:00:34 2005