[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: using por numbers in selectors
>>>>> "Derrell" == Derrell D Piper <ddp@Network-Alchemy.COM> writes:
Derrell> Fine, the first fragment containing the upper-level protocol
Derrell> header may have gone a different route. However, if you let
Derrell> the rest of the fragments through as a result, I'd argue you
Derrell> have a security hole.
And if you block them, you have a black hole. You have a problem
either way, just a different problem.
I think the only real answer is: if you do port based stuff, make sure
there is no fragmentation of the cleartext. Otherwise, the world will
be flaky at best.
paul
References: