[ExtractStream] Re: Status of Windows tools ==> Linux Solutio ns

Barcinski, Andy andy at a...
Thu, 11 Oct 2001 13:23:43 -0500


> > which says, "if a packet hits the firewall's port 8080 
> forward to this
> > host on the internal network at port 80." Of course I 
> can't leave that
> > open because there's no authentication on the web-server now.
> 
> 
> You wouldn't want to either. A DOS on your tivo is quite easy to
> accomplish if ANY services are open to the public. Nothing like
> watching a show an suddenly it studders, pauses, and then your
> tivo reboots. :(

DOS is remarkably easy, I agree. I portscanned my TiVo once, and that was
the end :-).

Why not use source-based filtering and only allow secure hosts to access it?
Most likely, if you are accessing from work, you are coming from the same IP
always, or within a subnet.