|
From: <hzu...@ra...> - 2004-03-16 18:50:16
|
On 03/16/2004 01:40:03 PM Bruce Smith wrote: >> >Interesting on one side and possibly dangerous on the other. At least >> >the >> >user has to actively install it to get it working. So what do you >think? >> > >> >><http://freshmeat.net/projects/ipt_sysrq/?branch_id=48664&release_id=15 >4 >> >413> >> > >> >IP Tables network magic SysRq 0.2 (Default) >> >by Marek Zelem - Monday, March 15th 2004 08:50 PST Section: >> >Software >> > >> >About: >> >IP Tables network magic SysRq is a Linux iptables target that allows >to >> >do the same as the magic SysRq key on a keyboard does, but over the >> >network. It includes syncing disks, remounting them read-only, >rebooting >> >the machine, etc. >> > >> >Release focus: Initial freshmeat announcement >> >> I'd say include it, it sound very interesting. > >This is only useful if (according to the docs): "Sometimes a remote >server hangs and only responds to icmp echo request (ping)." > >Yeah, I've seen that happen, but in my experience, it's very rare. >How useful is this really going to be? (just wondering :) For example when your box is hundrets of miles away, or your just to lazy to get up. >> I'm sure they come up with some better authentication in the future. > >Or even better authorization. :-) Minor details..... ;-) Heiko |
|
From: Bruce S. <bw...@ar...> - 2004-03-16 19:01:04
|
> >> >About: > >> >IP Tables network magic SysRq is a Linux iptables target that allows > >to > >> >do the same as the magic SysRq key on a keyboard does, but over the > >> >network. It includes syncing disks, remounting them read-only, > >rebooting > >> >the machine, etc. > >> > > >> >Release focus: Initial freshmeat announcement > >> > >> I'd say include it, it sound very interesting. > > > >This is only useful if (according to the docs): "Sometimes a remote > >server hangs and only responds to icmp echo request (ping)." > > > >Yeah, I've seen that happen, but in my experience, it's very rare. > >How useful is this really going to be? (just wondering :) > > For example when your box is hundrets of miles away, or your just to lazy > to get up. OK, you sold me, I'm lazy! :-) > >> I'm sure they come up with some better authentication in the future. > > > >Or even better authorization. :-) > > Minor details..... ;-) Either one would be an improvement! :-) This also caught my eye in the documentation: "Note that UDP port 9 is determined by a send_sysrq program and you can change it by editing the send_sysrq.c file." What, the guy can't make it a command line parameter or have it read a config file? Sheesh!!! - BS |
|
From: Bruce S. <bw...@ar...> - 2004-03-16 19:08:52
|
> > >> I'm sure they come up with some better authentication in the future. > > > > > >Or even better authorization. :-) > > > > Minor details..... ;-) > > Either one would be an improvement! :-) WAIT A MINUTE! (imagine light bulb going on over my head :) You supply two prime numbers (manually) while running "make". This would be in the DL build process? This means the encryption is static and can only be changed by recompiling DL? This means the key is burned on the CD and is the same for everyone with a stock distro? SECURITY HOLE!!! I changed my mind about including this! Or at least turn it off by default for all distro's available for download. YUCK! - BS |
|
From: Friedrich L. <fl...@fl...> - 2004-03-16 19:43:53
|
Bruce Smith wrote on 16.03.2004 20:08 MET: >>>>>I'm sure they come up with some better authentication in the future. >>>> >>>>Or even better authorization. :-) >>> >>>Minor details..... ;-) >> >>Either one would be an improvement! :-) > > > WAIT A MINUTE! (imagine light bulb going on over my head :) > > You supply two prime numbers (manually) while running "make". > This would be in the DL build process? This means the encryption is > static and can only be changed by recompiling DL? This means the key > is burned on the CD and is the same for everyone with a stock distro? > SECURITY HOLE!!! I changed my mind about including this! Or at least > turn it off by default for all distro's available for download. YUCK! I know. But you would not enable it from any IP, would you? Maybe those numbers can be supplied on some other way in the future. May let's mail the author. What do you think? -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <bw...@ar...> - 2004-03-16 19:54:32
|
> > You supply two prime numbers (manually) while running "make". > > This would be in the DL build process? This means the encryption is > > static and can only be changed by recompiling DL? This means the key > > is burned on the CD and is the same for everyone with a stock distro? > > SECURITY HOLE!!! I changed my mind about including this! Or at least > > turn it off by default for all distro's available for download. YUCK! > > I know. But you would not enable it from any IP, would you? But IP spoofing is easy, and it's not like there is a conversation going on. All someone has to do is spoof the source IP and send a packet. > Maybe those numbers can be supplied on some other way in the future. > May let's mail the author. What do you think? Yes, it would be nice if the numbers could be supplied as an option when loading the module, and as an option in the client program (along with the port number). As it is now, I wouldn't include it in DL. - BS |
|
From: Diego T. <dt...@co...> - 2004-03-16 22:58:40
|
On Tue, Mar 16, 2004 at 02:54:28PM -0500, Bruce Smith wrote: > > > > I know. But you would not enable it from any IP, would you? > > But IP spoofing is easy, and it's not like there is a conversation going > on. All someone has to do is spoof the source IP and send a packet. i dare you to do any ip spoofing nowadays :) you isp has filters that prevents you from doing that... for sure! > > Maybe those numbers can be supplied on some other way in the future. > > May let's mail the author. What do you think? > > Yes, it would be nice if the numbers could be supplied as an option when > loading the module, and as an option in the client program (along with > the port number). As it is now, I wouldn't include it in DL. if the author has made the port number configurable, i don't think that he/she has/wants to put more effort on it... -- -- gnupg keyfingerprint -- 48AF 5BF9 8F54 2966 64CC 2327 7CD0 DD91 B09D 5799 -- Use of a keyboard or mouse may be linked to serious injuries or disorders. Diego Torres - dtorres at anthalia dot org - Madrid / España |