View Single Post
  #13  
Old 08-19-2004, 06:11 PM
GrowlZ1010 GrowlZ1010 is offline
defunct
Join Date: May 2002
Posts: 187
GrowlZ1010 is on a distinguished road
Proxies are useful for some things, but this misfeature just makes life easier for those who would seek to compromise your server. Which of these two scenarios looks easier to you?

"Hmm! I can break GrowlZ' randomly-generated password, then somehow find a way to spoof a TCP connection as coming from me even if GrowlZ is offline and I can't dupe his computer into communicating with me instead of listserver.graalonline.com!"
or..
"I'll get this idiot's password and proxy password over Windows File Sharing then I'll log into his RC with no IP spoofing whatsoever needed. Yay!"

Every little helps. And proxies do have legitimate uses in some things, without a doubt. But IP ranges are there for a reason and should be used whereever possible.
Reply With Quote