Penetration Testing mailing list archives

Re: DROP or REJECT that is the question...


From: Isaac Perez <suscripcions () tsolucio com>
Date: Thu, 05 Apr 2007 13:57:52 +0200

The question is: You want to give information to the users (reject) to
help troubleshooting or you want to hide the information (drop) to the
attackers so they have less information to prepare the attacks?



El mar, 03-04-2007 a las 10:07 +0200, Mohamed Abdel Kader escribió:
All,

I wanted to gather your opinions on whether firewall rules should be Dropped

Or Rejected. To me I believe that both give away the firewall rules.

 

What does everyone out there think?

 

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------




------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: