Re: Messages in log with SNAT target

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, 24 Jul 2006, Anssi Hannula wrote:

Sietse van Zanen wrote:
The security risk is, and it is a MAJOR one, especially with WiFi networks is that any PC on the network could just be set up with a private IP on your private network, start sniffing for passwords etc.

It's a very, very bad idea to put your public and private WiFi infratructure on the same physical network.
I would say, there's even no point in firewalling this. Firewalling is seperating, you are combining.

-Sietse

In this case the private network is only a very small home network. I
don't see there being too big a risk of anyone setting up a box with
private IP on the network with harm on their mind. If that would be
possible, wouldn't the security of the whole system be compromised so
much that the private/public separation doesn't matter anymore?

The main purpose of the private IPs here is the ease of use and having
no public IP for a system if so wanted.


Hopefully, for yer sake, you are the only home for mile and miles around....Yet, I doubt such is the case, so you are a risk to all sadly.


Thanks,

Ron DuFresne
- -- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        admin & senior security consultant:  sysinfo.com
                        http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

...We waste time looking for the perfect lover
instead of creating the perfect love.

                -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFExrnlst+vzJSwZikRAmJzAKCtIckZvIFANrjxCKXZABSjyef5agCfUGQa
2E9jKQ6ooFwZUHzFZWTIYaI=
=OlhV
-----END PGP SIGNATURE-----


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux