Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Error 403 - Primitive Security Measures on the Forum

    Scheduled Pinned Locked Moved General pfSense Questions
    57 Posts 12 Posters 11.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NOYB
      last edited by

      @Quantum`:

      Frankly I'm pretty put off at this point by the complete lack of any apparent knowledge or discussion of the actual technical characteristics of pfSense.

      Your very first post here:
      @Quantum`:

      Wow, I am surprised and disappointed with the elementary security measures on the pfSense forum.

      This is supposed to be an advanced firewall, and yet you rely on Project Honeypot for the forum?  Which blocks the TOR browser?  And what's with the dumb questions at the bottom of every new post which never change? ("What is 5 + 6?" "Are you a spammer?  (yes / no)" "What is 10 + 5?")

      I hope the firewall isn't maintained by the same guys who run the forums.  I'm not sure at this point if I want to learn the firewall, if it's by amateurs.

      Entering a forum with inflammatory and demeaning accusations right from the start with your very first post is not the way to elicit a discussion.  But it's a pretty effective means of picking a fight.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        :o)

        We should just let the troll toddler die of starvation and keep this thread from going to three pages.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          Better yet, can someone press the lock button, please?

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            Thats so primitive…

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              @kejianshi:

              Thats so primitive…

              1 Reply Last reply Reply Quote 0
              • J
                jonesr
                last edited by

                @Quantum`:

                Frankly I'm pretty put off at this point by the complete lack of any apparent knowledge or discussion of the actual technical characteristics of pfSense.

                Beyond mentioning it is based on FreeBSD 10.1 and a fork of the m0n0wall project in response to your comments about Windows, and repeating there is some arms-length between the actual firewall product and the forum hosting service, it is a broad subject. You don't appear to have asked any questions regarding pfSense itself, what is it you wanted to discuss?

                pfSense AMD64 VGA - Assume latest version.
                Suricata, pfBlockerNG, SquidGuard, squid3.

                1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM
                  last edited by

                  Anyone else's Smite counts going through the roof lately?  I've had 4 since yesterday even after I stopped responding to Quantum.  I have a feeling that this Quantum guy is still having a tantrum and is coming here just to smite anyone who told him off.  So childish.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Yeah, 5 6 so far from the little skin flutist.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      Yep, I'm up to 17 now.  Was at 11 or 12 this morning.  He is literally going over every single post of ours and smiting them.

                      Jim, Chris or Steve, can you please do something about this guy?

                      1 Reply Last reply Reply Quote 0
                      • N
                        NOYB
                        last edited by

                        @KOM:

                        Anyone else's Smite counts going through the roof lately?  I've had 4 since yesterday even after I stopped responding to Quantum.  I have a feeling that this Quantum guy is still having a tantrum and is coming here just to smite anyone who told him off.  So childish.

                        @Derelict:

                        Yeah, 5 6 so far from the little skin flutist.

                        @KOM:

                        Yep, I'm up to 17 now.  Was at 11 or 12 this morning.  He is literally going over every single post of ours and smiting them.

                        Jim, Chris or Steve, can you please do something about this guy?

                        Well maybe if you all didn't have such a need to be right all the time…  ;)  ...you would get along better with others and trolls.  ;)  Nobody likes a know-it-all.  ;)

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Well maybe if you all didn't have such a need to be right all the time…  ;)

                          Being right is why karma here goes up.

                          Nobody likes a know-it-all.  ;)

                          Exactly.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • KOMK
                            KOM
                            last edited by

                            Nobody likes a know-it-all.

                            I don't know anything.  Just ask my wife.

                            Oh look,  I'm up to 18 now.  And by wild coincidence, Quantum logged in recently.

                            Anyway, I'm done with this thread.

                            1 Reply Last reply Reply Quote 0
                            • Q
                              Quantum 0
                              last edited by

                              In this life…  there are the smarter ones;  and then there are the dumber ones.

                              Just an abstract philosophical observation.

                              I've told the ones who matter what my plans are now for my Xen system, and what role (if any) that pfSense will play.  Most of you don't want to know though.

                              Bye.

                              1 Reply Last reply Reply Quote 0
                              • F
                                fsansfil
                                last edited by

                                @Quantum`:

                                In this life…  there are the smarter ones;  and then there are the dumber ones.

                                Just an abstract philosophical observation.

                                I've told the ones who matter what my plans are now for my Xen system, and what role (if any) that pfSense will play.  Most of you don't want to know though.

                                Bye.

                                Bear in mind that there will always be smarter and dumber than you…Just an abstract philosophical observation.

                                F.

                                1 Reply Last reply Reply Quote 0
                                • N
                                  NOYB
                                  last edited by

                                  @Quantum`:

                                  I've told the ones who matter what my plans are now for my Xen system, and what role (if any) that pfSense will play.  Most of you don't want to know though.

                                  Bye.

                                  Not if you are unable to express it without insults.  Which could be a significant indicator of your place on the smarter / dumber scale.

                                  Wow.  More than 100 smites per post so far, and no applause.

                                  1 Reply Last reply Reply Quote 0
                                  • ?
                                    Guest
                                    last edited by

                                    And, of course, today someone DOSed the forum.

                                    1 Reply Last reply Reply Quote 0
                                    • N
                                      NOYB
                                      last edited by

                                      @gonzopancho:

                                      And, of course, today someone DOSed the forum.

                                      It ain't no big thing.  We can wait for their adolescent temper tantrum to be over.  That's just part of living with 6+ billion spoiled adolescent brats.

                                      The pfSense forums use of Project Honey Pot has just be validated.

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        doktornotor Banned
                                        last edited by

                                        @gonzopancho:

                                        And, of course, today someone DOSed the forum.

                                        That of course was extremely mature and not primitive at all…  ;D ::)

                                        1 Reply Last reply Reply Quote 0
                                        • K
                                          kejianshi
                                          last edited by

                                          I didn't notice the DOSing…  Was the site down for .64 seconds or something?

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            cmb
                                            last edited by

                                            @Quantum`:

                                            Wow, I am surprised and disappointed with the elementary security measures on the pfSense forum.

                                            You emailed me asking about why you couldn't reach the forum from your server. I replied asking what its IP is, and you replied you were actually talking about Tor. I replied that yes, often httpBL ends up with Tor exit nodes' IPs blocked because they're frequent sources of abuse, and that if it were easy to just exclude Tor exit nodes, I'd do it. We have no intention of blocking Tor, we just block IPs that are actively spamming and abusing things per httpBL.

                                            We're running anti-spam measures that are common to many, many websites. Anyone who's run a popular forum knows the onslaught of abuse you deal with. The anti-spam measures unfortunately have to go to great lengths to keep the site from being flooded with spam registrations and posts. It has nothing whatsoever to do with security.

                                            @Quantum`:

                                            If I were to put spam in the forum, is there no control?  Are there no moderators who could ban me?  Would a spam post upset things such that everyone is thrown off-balance and the world goes higgledy-piggldy, and nothing could be done about it?

                                            We'd rather not have to hire someone full time to sit here and clean up spam, which is truly what would be required without spam prevention measures that are painful at times for a tiny fraction of a percent of users. You've clearly never run a popular website that accepts user-submitted content of any type.

                                            Project Honeypot is actually really good at this type of thing, and a significant improvement from "Stop Forum Spam" that we used prior to switching over to it. SFS and many similar options leave IPs blacklisted for months or years past the last known malicious activity from that IP, so it ends up blocking tons of IPs in ISPs' dynamic IP pools that had a compromised machine months or years previously when it was assigned to a different customer. httpBL is configurable for how recently you care about abuse. We use 30 days, and a pretty high threshold for "badness", so only IPs that have been significantly malicious in the past 30 days are affected. Unfortunately, that catches Tor exit nodes from time to time. Outside of Tor exit nodes, it has a very low rate of false positives. We get maybe 1 complaint a month on average with false positives outside of Tor (generally IPs used by those behind CGN), and it blocks upwards of 2000 requests a day on average. And httpBL is willing to whitelist Tor exit nodes if you submit them.

                                            @Quantum`:

                                            Frankly I'm pretty put off at this point by the complete lack of any apparent knowledge or discussion of the actual technical characteristics of pfSense.

                                            If you want to talk about technical characteristics, start a thread asking about technical characteristics. If you want to create a shit storm, start a thread bitching about commonly employed spam prevention measures that are standard to any popular forum on the Internet that isn't overrun with spam.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.