 ghost16825 Use security metrics Premium join:2003-08-26
| reply to gkweb Re: [Kerio 2.x] Kerio 2.15 w good rules fails 50%
Hard to believe, but my attack really wasn't intended to be on your website gkweb, but on the author of the application DNSTest and perhaps some of the other leaktest authors. I thought the definition of "leaktest" was something which bypassed a firewall completely, completely unseen by the firewall regardless of whether such traffic was allowed or not. Sure, if there's anything which does such a thing call it a leaktest and make sure it is publicised everywhere. (Some of the raw sockets type tests maybe). But suggesting massive security implications for everyone (as your website makes it out to be) - surely this is misleading. Most exploit implicit firewall rules and it would probably be more factual to try and describe in depth how these programs work and then let users decide how serious it is. This would be better than simply agreeing that the sky is falling and giving most of these authors kudos which they do not deserve. |