Re: [NTLK] Newtontalk digest stopped by spam filter

From: Paul Guyot (pguyot_at_kallisys.net)
Date: Sun Jan 25 2004 - 13:20:34 PST


On Sun, 25 Jan 2004, Grant Hutchinson wrote:

> In a previous message, Michael Blazer typed vigorously:
>
> >The folks developing the Newton Personal Data Sharing (NPDS) protocol,
> >http://npds.free.fr, should think about the consequences of using
> >URLs with non-common port numbers...
>
> And certain un-named, Pacific Northwest-based software companies should
> think about the consequences of continually creating easily exploitable
> operating systems and client-side email applications...

And web servers.

Actually, NPDS can run on any port. We choose to run our servers on port
8080 or 8000 or the like mostly because a server on port 80 will be the
target of CodeRed and other Nimba viruses that spread on unpatched IIS
servers. And these attacks can crash our Newtons. The two Newtons with the
highest hit count run on 8080. It's been weeks since I had to manually
restart my Newton and I think I woulnd't have crashed Grant's with my
tests with the whiteboard feature, his Newton could have continued for
weeks as well. Let us run on 80 and we can't keep running that long. On
8080, the only thing we can see is stupid hackers trying to use our
Newtons as HTTP proxies, asking them to serve www.google.com (I always
laugh when I see that, maybe one day I'll make a special NPDS honey-pot
module).

The 3680 port for HTTP requests is non standard indeed, but it makes the
NPDS tracker very simple and easy to deploy (no need for a standalone web
server for example). And as Grant pointed out, this is an official port
assigned by IANA. It took us two months to get it, but we finally did
and it's better than the 2110 Matt used to run his tracker on. We can
add GET as a method in the protocol anytime and make URLs like
http://npds-tracker.continuity.cx:3680/ perfectly standard.

Paul

-- 
This is the NewtonTalk list - http://www.newtontalk.net/ for all inquiries
List FAQ/Etiquette/Terms: http://www.newtontalk.net/faq.html
Official Newton FAQ: http://www.chuma.org/newton/faq/


This archive was generated by hypermail 2.1.5 : Sun Jan 25 2004 - 14:00:02 PST