GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    tech (tech@unfufadoo.net)'s status on Monday, 31-Mar-2025 08:32:17 JST tech tech

    #tech #photos #heldesk #images #infosec #memes #cloud #sysadmin #funny

    In conversation about 9 months ago from unfufadoo.net permalink

    Attachments


    1. https://unfufadoo.net/system/media_attachments/files/114/253/759/576/844/852/original/ea3d01a60f0e649c.jpeg
    • feld likes this.
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:26:08 JST feld feld
      in reply to
      • `Da Elf
      • I am Water
      @SlicerDicer @tech @elfin People who block all ICMP deserve to be fired for incompetence. You can filter out the dangerous ICMP types without breaking echo/echoreply (0 and 8)
      In conversation about 9 months ago permalink
    • Embed this notice
      I am Water (slicerdicer@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:26:09 JST I am Water I am Water
      in reply to
      • `Da Elf
      @tech @elfin Disable ping what do you do?
      In conversation about 9 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:37:00 JST feld feld
      in reply to
      • `Da Elf
      • I am Water
      @SlicerDicer @tech @elfin If it's blocked completely you'll break PMTU which can cause network requests to hang / fail
      In conversation about 9 months ago permalink
    • Embed this notice
      I am Water (slicerdicer@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:37:01 JST I am Water I am Water
      in reply to
      • `Da Elf
      • feld
      @feld @tech @elfin I blocked it on my network lol
      In conversation about 9 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:46:32 JST feld feld
      in reply to
      • `Da Elf
      • I am Water
      @SlicerDicer @elfin @tech also I'm wrong on the specific types, I get the names and numbers mixed up. I have them documented for pf and ipfw both v4 and v6, I'll send them.

      You need to be able to respond with a fragmentation needed message and it's not echoreply for that one, I think it's type 3 / destination unreachable
      In conversation about 9 months ago permalink
    • Embed this notice
      I am Water (slicerdicer@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:46:33 JST I am Water I am Water
      in reply to
      • `Da Elf
      • feld
      @feld @tech @elfin It’s not completely, just my external. I don’t want to see it in my logs.
      In conversation about 9 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:55:37 JST feld feld
      in reply to
      • `Da Elf
      • feld
      • I am Water
      @SlicerDicer @elfin @tech

      ok for ICMP you want: 0,3,8,11

      You could block 0 and 8 so the normal ping doesn't work, but you really don't want to block 3 and 11 or when shit goes wrong the machine on the other end doesn't get the hint (packet too large, exceeds TTL)
      In conversation about 9 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Tuesday, 01-Apr-2025 11:59:32 JST feld feld
      in reply to
      • `Da Elf
      • feld
      • I am Water
      @SlicerDicer @elfin @tech for ICMP6 you really need:

      135 neighbrsol Neighbor solicitation
      136 neighbradv Neighbor advertisement

      because those are basically the IPV6 version of ARP

      You probably want:

      1 unreach Destination unreachable
      2 toobig Packet too big

      You can live without, but it's worth having

      128 echoreq Echo service request
      129 echorep Echo service reply

      and you should only have these on your own networks where you need them:

      133 routersol Router solicitation
      134 routeradv Router advertisement


      the rest should all be blocked
      In conversation about 9 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.