![]() |
|||||
Defenses Against DoS AttacksTurning Off IP ForwardingFor Solaris 2.5 and above: Preventing incoming broadcast packets from entering your networkAdd the following at the end of /etc/rc2.d/S69inet: Preventing the system from responding to incoming broadcast packetsAdd the following command at the end of /etc/rc2.d/S69inet: TCP WrappersThe source code for this freeware tool, written by Wietse Venema, is compiled to produce the tcpd binary, which can be used to wrap a number of network services (e.g., ftp, telnet, finger). The package also provides the capability to capture client host name and requested service information. When used to wrap TCP services, the package provides the following optional features:
S/KeyS/Key is a one-time password mechanism. It provides protection against password replay attacks. With S/Key, you use information presented in the remote system's login challenge, along with a password, to compute a passphrase on your local host. If the computed passphrase is correct, you are given access the remote host, and the remote system marks the computed passphrase so it cannot be used for future sessions. WU-ftpdWu-ftp provides additional access controls and extensive logging facilities. |
Our Publications |