Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-11 Thread Juergen Christoffel
On Thu, Apr 10, 2014 at 11:32:21PM -0700, Paul Vixie wrote: [...] really bruce? on a scale of doesn't-matter-at-all to worst-thing-you-could-have-previously-imagined, a read only exploit is even worse than that? With all due respect to your ego Paul, I think you might under-estimate the long te

Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-09 Thread Juergen Christoffel
On Wed, Apr 09, 2014 at 09:24:25PM +0200, Reindl Harald wrote: iptables logging needs to be rate-limit always because how it works otherwise you have a problem the first time it really happens seriously Using limits is sensible, yes. But -m limit --limit 1/m this might be a bit too restric