Slashdot Mirror


Run Your Firewall Halted for Extra Security

n8willis writes: "There's a great article over at the SysAdmin magazine site that presents a unique approach to improving network security: run your firewall in a halted state. This means runlevel 0; no processes running and no disks mounted, but with packet filtering still on. The author heard a rumor of this capability in the 2.0 series kernels, and he's managed to get it working in 2.2 as well."

16 of 390 comments (clear)

  1. VANILLA ICE by Anonymous Coward · · Score: -1, Offtopic
    Second prost, homiez!


    Eminem's mom says hi (from under my desk).


    VI

  2. hey its..... by Anonymous Coward · · Score: -1, Offtopic

    frosty pist

  3. First post by Anonymous Coward · · Score: -1, Offtopic

    Haha

  4. FfiIrRsStT PpOoSsTt by Anonymous Coward · · Score: -1, Offtopic

    First post, will robinson.

  5. You are powerless against by Saint+Aardvark · · Score: -1, Offtopic
    my army of Zombie firewalls! I shall RULE THE INTERNET! Hahahahahahahaha!

  6. Network? by Anonymous Coward · · Score: -1, Offtopic

    Would it be possible to log that kind of stuff to another host on the network? Not sure if that's really possible or not...

  7. PLP by Anonymous Coward · · Score: -1, Offtopic

    7
    5
    7
    9
    4
    6
    0
    4
    4
    2
    9
    6
    5
    6
    7
    1
    7
    3
    1
    3
    3
    5
    8
    3
    5
    6
    7
    8
    3
    2
    0
    1
    4
    7
    1
    2
    9
    2
    6
    2
    7
    6
    6
    3
    7
    8
    9
    4
    5
    6
    4
    5
    4
    0
    5
    1
    0
    9
    8
    9
    6
    8
    2
    9
    8
    9
    0
    3
    2
    6
    9
    2
    7
    7
    0
    1
    0
    9
    6
    2
    1
    9
    0
    1
    1
    7
    0
    9
    4
    5
    0
    3
    4
    1
    5
    7
    7
    1
    9
    6
    0
    5
    8
    2
    9
    9
    7
    3
    2
    5
    0
    3
    8
    4
    4
    7
    2
    2
    3
    8
    1
    7
    6
    3
    5
    7
    9
    3
    2
    6
    4
    6
    2
    5
    6
    1
    4
    2
    2
    4
    1
    3
    0
    8
    7
    1
    0
    7
    7
    2
    3
    6
    3
    7
    4
    3
    6
    4
    5
    6
    6
    5
    9
    6
    6
    4
    1
    9
    5
    8
    1
    8
    5
    0
    7
    6
    3
    4
    5
    3
    1
    4
    1
    2
    2
    5
    7
    8
    6
    7
    3
    7
    3
    9
    0
    1
    9
    8
    5
    5
    6
    9
    8
    8
    1
    2
    1
    4
    7
    3
    4
    2
    4
    4
    8
    5
    3
    4
    1
    2
    3
    4
    3
    3
    6
    0
    3
    3
    8
    3
    7
    8
    9
    6
    8
    9
    7
    6
    2
    3
    3
    0
    2
    5
    3
    8
    3
    5
    6
    5
    2
    9
    3
    1
    5
    4
    6
    0
    2
    9
    3
    5
    8
    7
    7
    1
    9
    5
    2
    8
    1
    1
    3
    6
    4
    8
    6
    3
    8
    0
    7
    9
    5
    2
    6
    5
    1
    9
    7
    0
    3
    1
    0
    2
    9
    0
    3
    5
    3
    9
    2
    5
    8
    7
    0
    3
    6
    5
    0
    6
    1
    9
    6
    9
    6
    6
    8
    2
    0
    7
    1
    2
    1
    4
    8
    1
    9
    8
    9
    0
    8
    7
    6
    3
    4
    1
    8
    2
    2
    0
    3
    4
    5
    2
    7
    5
    8
    6
    8
    8
    2
    7
    2
    7
    2
    1
    5
    6
    8
    9
    8
    8
    7
    1
    1
    9
    8
    2
    8
    6
    9
    6
    4
    2
    8
    8
    3
    9
    9
    4
    3
    1
    8
    8
    2
    8
    1
    7
    7
    6
    8
    1
    4
    9
    8
    7
    6
    0
    1
    8
    4
    5
    1
    8
    0
    7
    2
    5
    7
    3
    2
    6
    2
    6
    8
    9
    4
    4
    3
    6
    3
    7
    8
    5
    9
    6
    4
    8
    8
    1
    3
    9
    8
    2
    4
    0
    9
    7
    6
    3
    1
    8
    4
    4
    2
    1
    2
    9
    1
    8
    4
    2
    1
    4
    9
    9
    5
    1
    1
    8
    5
    1
    5
    4
    3
    7
    4
    6
    8
    7
    2
    0
    8
    7
    0
    4
    0
    1
    2
    8
    6
    2
    9
    9
    9
    6
    1
    3
    6
    3
    4
    1
    4
    4
    6
    1
    3
    3
    5
    0
    6
    4
    8
    7
    1
    0
    5
    9
    6
    4
    6
    4
    1
    8
    2
    1
    4
    8
    5
    5
    5
    7
    9
    1
    5
    9
    8
    1
    9
    0
    3
    6
    0
    5
    6
    1
    3
    8
    5
    3
    5
    7
    6
    7
    9
    5
    0
    2
    4
    7
    0
    4
    3
    2
    2
    3
    3
    0
    1
    1
    5
    1
    2
    9
    8
    6
    6
    3
    6
    5
    4
    1
    7
    4
    1
    5
    4
    7
    8
    7
    7
    9
    7
    0
    5
    0
    6
    0
    8
    6
    4
    1
    4
    7
    0
    1
    8
    4
    8
    0
    4
    1
    8
    6
    9
    4
    2
    7
    7
    5
    1
    8
    1
    2
    6
    1
    2
    3
    8
    7
    7
    2
    9
    1
    8
    0
    0
    8
    8
    5
    2
    2
    0
    7
    2
    3
    9
    3
    0
    3
    2
    0
    5
    1
    4
    1
    8
    7
    9
    3
    4
    8
    8
    5
    4
    8
    0
    0
    8
    3
    5
    7
    9
    9
    5
    6
    2
    6
    5
    7
    4
    2
    2
    5
    4
    9
    3
    3
    3
    6
    6
    1
    7
    5
    8
    2
    2
    3
    2
    1
    9
    0
    8
    4
    0
    9
    3
    8
    3
    8
    4
    3
    5
    2
    8
    9
    4
    7
    6
    5
    2
    9
    8
    8
    4
    5
    6
    8
    2
    4
    9
    2
    9
    4
    4
    5
    4
    1
    7
    6
    0
    3
    5
    7
    4
    4
    6
    6
    0
    8
    1
    4
    3
    3
    7
    7
    1
    0
    9
    2
    4
    0
    2
    7
    4
    8
    1
    5
    1
    4
    0
    1
    9
    7
    5
    6
    0
    5
    6
    6
    8
    6
    7
    5
    9
    8
    6
    8
    1
    6
    5
    8
    9
    1
    5
    6
    7
    7
    6
    1
    3
    8
    3
    4
    5
    2
    2
    7
    3
    5
    1
    2
    4
    7
    0
    5
    9
    2
    8
    4
    1
    5
    2
    5
    7
    5
    9
    1
    5
    5
    9
    0
    8
    1
    1
    8
    2
    4
    3
    6
    5
    3
    6
    4
    1
    3
    8
    2
    3
    6
    6
    6
    5
    2
    8
    8
    8
    1
    9
    3
    3
    5
    5
    9
    9
    3
    6
    3
    8
    5
    8
    0
    6
    8
    1
    4
    6
    8
    0
    1
    3
    8
    1
    5
    0
    1
    0
    4
    3
    0
    7
    5
    6
    2
    4
    3
    4
    2
    1
    1
    6
    0
    2
    4
    5
    9
    1
    5
    4
    8
    3
    0
    7
    7
    8
    3
    1
    6
    6
    9
    2
    8
    5
    7
    0
    0
    3
    9
    5
    8
    8
    4
    2
    3
    5
    7
    4
    5
    8
    6
    0
    5
    4
    4
    7
    2
    9
    2
    2
    1
    5
    1
    5
    7
    6
    1
    0
    2
    0
    5
    2
    0
    0
    4
    2
    9
    4
    4
    1
    5
    5
    1
    9
    4
    3
    0
    2
    3
    6
    2
    9
    0
    4
    5
    2
    4
    4
    9
    1
    4
    2
    6
    4
    6
    1
    1
    1
    1
    7
    2
    9
    9
    5
    1
    8
    9
    6
    5
    4
    8
    3
    7
    8
    8
    0
    8
    5
    9
    1
    3
    8
    9
    8
    9
    2
    7
    3
    8
    3
    3
    1
    7
    6
    5
    0
    6
    0
    4
    2
    5
    2
    6
    3
    7
    3
    8
    2

    In the wake of the dot-com washout, a lot people nearly wrote off cyberspace as a retailing wasteland. But last week, Amazon reported that it had finally turned a profit, something most of us thought we'd never see, and preliminary figures show a sharp upturn in online sales despite the mild recession. Some other interesting post-Christmas tidbits are popping up, too: for the first time, more women than men are buying things online, a landmark barometer of a bright digital retailing future. Beyond that, in case you haven't noticed, online retailers are getting a lot smarter. The arrogant, customer-abusive tech world could learn a lot from these people, who offer steep discounts, stand behind their products, and actually offer real and free customer support.

    The final Christmas shopping figures for 2001 are not in, but some industry analysts believe the new savvy and sensitivity of online retailers might have rescued the U.S. Christmas shopping season in the wake of September 11, when a lot of people either stayed home or tightened their belts. "I can't be quoted on this until the figures are finished," a friend and research analyst e-mailed me, "but I believe online shopping really saved retailing last year. The sites and service are getting so much better, and consumer confidence in them -- especially among women -- is skyrocketing. Online retailing is not only on the rise, it's really getting to be fun and easier. More importantly, they grasp customer service, something almost no software or hardware company yet does."

    If that's so, and it definitely matches my personal shopping experiences, it's huge news for the Net. Consumers, chronically abused by the software and hardware industries, were initially anxious about buying things online. They worried about hackers, crackers and security; they faced poor customer service and complex downloading and other problems. But those problems -- unlike similar headaches in the larger computer industry -- are being addressed.

    Retailers competing online this holiday season were a lot shrewder, says a story on About.com about the online retailing industry.

    About.com cited a survey of 63 retailers who found a successful holiday season marked by a surprisingly effective combination of widespread promotions and discounting. Most consumers hate spam, but it doesn't bother them so much if it's about things they want, and if they're getting something for the attention. Both multichannel and Web-based retailers seemed to have learned a lot from past marketing missteps. The Shop.org/Boston Consulting Group (BCG) found that more advanced retailers, after carefully studying the economics of each online and offline promotion, are finding ways to offer the minimum discounts necessary for increasing sales volume and ways to deliver targeted promotions to the more than 100 million consumers estimated to have used the Net over the holiday season.

    Besides that, sites have radically improved their graphics and visual representations of products. As fears about theft and security have subsided, companies have radically upgraded their customer service. This is in striking contrast to tech industries which sell products that are confusing and difficult to use, and either makes themselves unavailable to confused or outraged customers or charge them extortionate fees for "priority service," which is really just the service they would be entitled to for free in any other business.

    If you want to see smart web businesses, I'd cite two in particular -- L.L. Bean and Pet Food Direct. L.L. Bean's site architecture is brilliant -- well organized, easy to navigate. It shows clear pictures of all of its products and allows easy customer access to account information, while still providing security. More interestingly, the site offers customers several ways to get instant help -- phone, instant messaging, nearly instant e-mail response. If you're encountering problems, you can simply e-mail or call and a human will respond promptly. This support is crucial to building consumer confidence. A shopper is much more likely to risk buying something online if they know they can get help with any problems. Tech shoppers are among the most distrustful on the planet after years of confusing products and poor service.

    Pet Food Direct also offers a different kind of targeted retailing, e-mailing customers weekly about specials, sales and promotions on the products they have already demonstrated they want and use regularly. This isn't quite like spamming, since it's stuff the buyer needs. And the sharp discounts have a way of offsetting any irritation. The site isn't trying to be funny or cute. Rather than promoting a silly sock puppet, it offers heavily discounted pet food and reminds pet owners when they are apt to need it. It also offers sophisticated graphic renderings of products and instant customer service both online and by telephone. The purchase takes seconds. The discounts are heavy enough to attract shoppers attention, but apparently not so heavy to erode profits. One reason is that the site, like L.L. Bean, gives the consumer a variety of shipping choices, from regular mail to next day air. And the customer pays for shipping, choosing exactly how much of a discount he or she wants. In both cases, the sites don't spam -- they target people who have bought and need their products.

    Dozens of other sites have similarly polished their presentation, honed their sense of marketing and discounting and, most importantly, invested in tech support and customer service. Shoppers feel secure not only through repeated use, but through the sense that somebody will speak to them if problems arise.This is something that, alas, computer and software companies still haven't learned.Globalization Posted by JonKatz on Tuesday October 30, @11:00AM
    from the the-cause-of-the-taliban-or-the-cure? dept.(First of two parts). Globalism is one of those notions much kicked around and little understood, shrouded in hysteria and knee-jerk cant. People with a host of grievances against technology, multinational corporations and capitalist democracies have made globalism a dirty word, at the same time that many social scientists and economists argue that the equitable spread of technology and a free-market economy is the planet's best hope. Either way, September 11 makes it clear that globalization - pitting fundamentalism against cosmopolitan tolerance - is one of the most important issues in our lifetimes. In fact, as British political scientist Anthony Giddens writes in his eerily prescient book Runaway World: How Globalism is Reshaping Our Lives, the conflict now underway between the United States and some extremist fundamentalists was inevitable. Cosmopolitans welcome technology and cultural diversity, while fundamentalists find it disturbing and dangerous. In a globalizing world -- one of its cornerstones being the Net -- technology, information, culture, money, business and imagery are routinely transmitted across the world. Boundaries mean different things now, including the inescapable fact that they are highly porous. This enrages political, social and religious fundamentalists, as we are hurriedly learning. They turn to religion, ethnic identity and nationalism to build "purer" traditions -- and a few turn to violence. So despite the fact that there's no consensus on exactly what globalism is (my dictionary defines it as the process by which social institutions become adopted on a worldwide scale), the questions torment us: is globalism a force to ease poverty and inequality, by bringing higher standards of living and new technologies to poor and distant regions? Or merely an unprecedented vehicle for promoting the greed, conformity, environmental destruction and profit-at-all-cost ethos of multinational corporations? Perhaps it's both. Giddens' predictions are coming true before our eyes. The conflict is here, and we seem to be unwilling and unknowing combatants. We, along with our leaders, are astonished at just how much we seem to be hated out there. We see our popular and technological culture despised in much of the world. Fundamentalist extremists have declared a holy war against it, one that may continue for years with bloody and uncertain consequences. It's not an oversimplification to say that technology is the prime battleground. Technologies from movie cameras to TV sets to the Net are the means by which culture and wealth travel from one part of the world to the other. Fundamentalists have declared war on technology as much as on anything. And from anthrax to passenger jets as missiles, they've shown a sophisticated grasp of how technology can be used to devastating effect against its creators, who revel in making it but not thinking much about it. In this conflict what Giddens calls "the cosmopolitan approach" is the choice of the people who are reading this column and working in the tech universe. We value free speech, religious freedom, scientific exploration, open communications, cultural choice and diversity. Such tolerance is closely conected to democracy. Yet democracy and fundamentalism are both spreading world-wide, two seemingly irreconcilable ideologies colliding head-on. As Giddens points out, globalism creates a paradox: democratic cultures are its most enthusiastic proponents, yet globalism doesn't seem to promote democracy so much as corporate profits and practices. In fact, you could argue that globalism seems to expose the limits of democratic structures: Can governments preserve the environment, keep work secure and equitable, ensure fair wages, control capitalism, distribute new technologies equitably, respect diverse cultural values, contain greed and restrict the imagery that Americans love but that frightens and offends large segments of the world population? In Part Two: Have multinationals hijacked globalism? (Yes.) Posted by JonKatz on Tuesday January 22, @11:00AM
    from the does-tech-connect-or-disconnect? dept.
    Do media/entertainment technologies connect or disconnect people? That Americans have become increasingly disconnected from one another and the social capital that binds people since the rise of TV and the Net is an idea much debated since Robert Putnam published Bowling Alone: The Collapse and Revival of American Community two years ago (the book is now out in paperback). The Net -- ironically the world' s most connective medium -- could be radically advancing that trend. Putnam cites numerous surveys that show that interaction with family, friends, and neighbors, and participation in social activities -- from joining civic groups and bowling leagues to voting -- has declined as Americans find more reasons to stay at home. Online, fragmentation abounds. People turn increasingly inward. The big open spaces of the Net have either been corporatized, flamed to death or shut down, and communications steadily turned to exclusive p2p "me media," the fragmented, often self-censored, personalized and specialized weblogs, IM programs and mailing lists that dominate much of online communications.

    In his book, Putnam argues that our access to the "social capital" that is the payoff for community and civic work is shrinking. Though the reasons are complex, technology and mass media are primary factors, Putnam says. We spend more time at home watching TV (and, increasingly, working and amusing ourselves online) and less with other people. Our detachment from communal efforts -- and opportunities to meet other people -- grows. In l960, 62.8 percent of voting-age Americans went to the polls to choose between John F. Kennedy and Richard M. Nixon; in l996, after decades of slippage, just 48.9 percent chose Bill Clinton over Bob Dole. The inverse correlation between the rise of screen-driven entertainment technologies and civic disconnection is persuasive. So is the epidemic hostility online.

    Although Putnam's book focuses on TV more than the Net (since TV is older and its use has been more widely studied), it's impossible not to think about the new ways networked computing may contribute to this disconnection. The Net is the world's greatest communications medium, but the notion of cyberspace as providing a social connection -- remember the virtual community? -- has turned out to be a fantasy. In many ways, the intensely connective Net is helping people become more disconnected all the time. It's the new TV.

    This is of no small consequence, Putnam argues. Social bounds are the most powerful predictor of life satisfaction. Communities with low social capital have poor schools, more teen pregnancies and child or youth suicide, and higher prental mortality. Social capital is also the most reliable indicator of crime rates and other measurable quality-of-life issues. Such disconnection has happened before in American life, Putnam writes, especially during periods of great migration and immigration, but it was reversed by periods of stability and the rise of organizations like the Red Cross, the Boy Scouts, and thriving religious organizations.

    Of all the many dimensions along which forms of social capital vary, writes Putnam, perhaps the most important is the distinction between "bridging" (or inclusive) and "bonding" (or exclusive). Some forms of social capital are, by choice or necessity, he writes, inward looking and tend to reinforce exclusive identities and homogeneous groups -- fraternal organizations, church-based women's reading groups, snooty country clubs. Other networks are outward looking and encompass people across diverse and different social networks -- youth service groups, civil rights organizations, ecumenical religious associations.

    The Net, it was originally believed, would be a "bridging" technology, one that would connect the planet. But the most interesting evolution in software in recent years has been code that permits people to narrow, not expand, their universes. Blocking and filtering software has become epidemic to product against flamers, crackers and spammers. The explosion in weblogs, specialized mailing lists, instant messaging and other so-called p2p media means that people online increasingly talk only to one another, not to people who are different or unfamiliar. The rise of this narcissistic communications is understandable, but it hardly is inclusive. People all over the Web routinely block and filter points of view they don't like or don't want to hear (or buy), so nobody online really ever has to encounter all that discordant diversity that digital technology makes possible. More disconnection.

    Thanks in part to the Net, Americans have never had so many reasons to stay home, so many entertaining or useful options when they do. I remember an e-mail I got from a grandmother last year lamenting all the TV ads showing AOL grandmas getting pictures of their grandchildren. "That's nonsense," she says. "My kids don't visit me nearly as much because they feel they can just e-mail me. I love digital pictures, but I rarely get to see my grandchildren in person." Her lament -- the illusion of connection, while facing the reality of tech-spawned separation -- was intriguing.

    The rise of the Net would seem to have exacerbated this tendency. Americans had already been spending an enormous amount of time watching television. Putnam found that 80 percent of all Americans watch some TV every evening, while only about 60 percent talk with their families nightly, let alone neighbors, strangers or others. Watching TV has become one of the few universal experiences of contemporary American life.

    Increasingly, the Net is one too. It promises consumer use as great as television's, if not greater, since work connects with home. This seems especially ironic, since the Net was supposed to be one of the most powerful devices ever for connecting with humans. Mostly, it connects us with bits and links. In a sense, it is a connective medium. We can stay in touch with friends, colleagues and family members all over the planet. But Americans use the Net to get free data from music to weather, send messages, play games, shop and talk about sex. So the Net could exacerbate the techno-trend that television began. We're e-mailing and browsing alone as well as bowling. The Net could have an ever more striking impact, since it enables users to do things TV doesn't -- like play games and shop for nearly everything. Those, among others, were activities that people once had to go outside to do, where they might glimpse or even speak with a neighbor -- or go bowling.

    America was founded partly on the notion of common civic spaces -- taverns, greens. A lot of cyber-idealists thought the Net was becoming our new common space. That hasn't happened. Nasty teenagers, spammers and greedy corporatists have made common turf on the Net either too expensive, hostile or annoying for most people to spend much time on.

    Putnam's idea about social capital might be even more timely relevant than he understood.

  8. Re:Another interesting consept: Invisible Firewall by Anonymous Coward · · Score: -1, Offtopic

    Because Theo whispered it into his ear as he gently slid his member in.

  9. Re:Another interesting consept: Invisible Firewall by Anonymous Coward · · Score: -1, Offtopic

    I suspected it was something along those lines, but I just wanted confirmation.

  10. Re:brilliant! by clmensch · · Score: -1, Offtopic

    Hah! That's what I was thinking.

    --
    There is no gravity...the earth just sucks.
  11. Did this accidentally once.... by ManualCrank+Angst · · Score: 0, Offtopic

    I had my server running the firewall. Needed to format a floppy. dd if=/dev/zero of=/dev/hda.....Oops. Say, honey, you better check your email one last time and then I'll reinstall the server.

    --
    Hate trolls? Troll 'em back...at home!
  12. Re:No processor running? by Anonymous Coward · · Score: -1, Offtopic

    I'm also always very interested in the thoughts of people who can't read.

  13. Re:More Secure Solution by Anonymous Coward · · Score: -1, Offtopic

    Why did this only get a 2?

  14. *** Linux boxes at Runlevel 0 *** by Anonymous Coward · · Score: -1, Offtopic

    Imagine a Beowolf Cluster of THESE!!!

  15. Re:brilliant! by mekkab · · Score: 0, Offtopic

    How is the above message off topic?!

    I hate moderators. I can't wait until I'm a moderator.

    Not only is the above either A) contradictory or B) a great example of my own self loathing, but ITS OFF TOPIC.

    please moderate me as such.

    --
    In the future, I would want to not be isolated from my friends in the Space Station.
  16. MOD THIS UP! by schroet · · Score: 0, Offtopic

    MOD THIS UP!