Ascend Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(ASCEND) Filters broken in 7.0b4



With earlier problems in release 7.0.0 and everything after and including
7.0b6, I had written that I was still running 7.0b4 and recommended that
anyone needing 7.0 features that actually wanted _stability_ in their code
should also consider using it until Ascend got their act together with 7.0
patches.

I ran 7.0b4 for almost three months on most of my systems,
(and only _one_ of them crashed in that entire time!)
but an incident yesterday changed all that.

Filtering (at least using Ascend-Data-Filter in a Radius profile)
was broken in 7.0b4, and allowed a Spammer to relay several thousand
messages through a mail server that was supposed to have been
protected from any external SMTP connections by the filters in my Max.
I do Anti-spoof filtering on my dial-in ports which also may have failed,
but thankfully I had no reports of any attacks originating from my dial-ins,
maybe I'm just lucky enough to have a decent user community.

I did an emergency upgrade on all my Maxen last night to 7.0.1,
and so far all is working properly, filtering, OSPF, etc.,
(only up for ten hours now...)

So, if you use filters and are still running any of the beta releases,
please test your filter policies to make sure they are working,
I'd really hate to see anyone else attacked through malfunctioning filters.

-Jim H
----
Jim Howard             Sr Network Engineer        Lyceum Internet
jhoward@lyceum.com     http://www.lyceum.com/     404.248.1733     

My PGP Public Key: http://www.lyceum.com/~jhoward/pgp-key.txt
Fingerprint: 7E8B E2BA 1314 2535 CB08  CFF9 119B 7CD3 2488 954D

++ Ascend Users Mailing List ++
To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
To get FAQ'd:	<http://www.nealis.net/ascend/faq>