[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: using por numbers in selectors



>>>>> "Derrell" == Derrell D Piper <ddp@Network-Alchemy.COM> writes:

 Derrell> Fine, the first fragment containing the upper-level protocol
 Derrell> header may have gone a different route.  However, if you let
 Derrell> the rest of the fragments through as a result, I'd argue you
 Derrell> have a security hole.

And if you block them, you have a black hole.  You have a problem
either way, just a different problem.

I think the only real answer is: if you do port based stuff, make sure 
there is no fragmentation of the cleartext.  Otherwise, the world will 
be flaky at best.

	paul


References: