URL: https://www.opennet.me/cgi-bin/openforum/vsluhboard.cgi
Форум: vsluhforumID1
Нить номер: 40021
[ Назад ]

Исходное сообщение
"sshd: warning: /etc/hosts.allow"

Отправлено AD , 02-Фев-04 05:51 
sshd[16983]: warning: /etc/hosts.allow, line 23: host name/name mismatch: reverse lookup results in non-FQDN 19
а вот это 23 строка
ALL : ALL : allow

что такое могло ему не понравиться?


Содержание

Сообщения в этом обсуждении
"sshd: warning: /etc/hosts.allow"
Отправлено Nightman , 02-Фев-04 07:05 
>sshd[16983]: warning: /etc/hosts.allow, line 23: host name/name mismatch: reverse lookup results in
>non-FQDN 19
> а вот это 23 строка
>ALL : ALL : allow
>
>что такое могло ему не понравиться?


# Protect against simple DNS spoofing attacks by checking that the
# forward and reverse records for the remote host match. If a mismatch
# occurs, access is denied, and any positive ident response within
# 20 seconds is logged. No protection is afforded against DNS poisoning,
# IP spoofing or more complicated attacks. Hosts with no reverse DNS
# pass this rule.
ALL : PARANOID : RFC931 20 : deny


"sshd: warning: /etc/hosts.allow"
Отправлено AD , 02-Фев-04 07:31 
># Protect against simple DNS spoofing attacks by checking that the
># forward and reverse records for the remote host match. If a
>mismatch
># occurs, access is denied, and any positive ident response within
># 20 seconds is logged. No protection is afforded against DNS poisoning,
>
># IP spoofing or more complicated attacks. Hosts with no reverse DNS
>
># pass this rule.
>ALL : PARANOID : RFC931 20 : deny

как поправить праильнее?


"sshd: warning: /etc/hosts.allow"
Отправлено Nightman , 02-Фев-04 07:55 
>># Protect against simple DNS spoofing attacks by checking that the
>># forward and reverse records for the remote host match. If a
>>mismatch
>># occurs, access is denied, and any positive ident response within
>># 20 seconds is logged. No protection is afforded against DNS poisoning,
>>
>># IP spoofing or more complicated attacks. Hosts with no reverse DNS
>>
>># pass this rule.
>>ALL : PARANOID : RFC931 20 : deny
>
>как поправить праильнее?
Можно заремить ALL : PARANOID : RFC931 20 : deny
но учти то что написано свыше..

ALL : PARANOID : RFC931 20 : deny убивало конекты идущие с хостов без реверсной или некорректно прописаной реверсной зоны (на INETD идущие)