WEBVTT

00:08.920 --> 00:14.640
Friends will come back in this lesson we we're going to learn about how to hold and who are in the clear.

00:14.700 --> 00:15.110
OK.

00:15.180 --> 00:19.150
Now Bruce listen we have to learn how to use the firewall.

00:19.170 --> 00:21.050
And so I was fine.

00:21.080 --> 00:21.590
OK.

00:21.800 --> 00:27.170
So listen we're going to learn more about Hoku harder the network here.

00:27.320 --> 00:27.760
OK.

00:28.070 --> 00:31.700
So let's see practically how to do this.

00:31.700 --> 00:34.810
OK I'll put up the file which is prison.

00:34.910 --> 00:37.560
It is a directory with sudo access.

00:37.810 --> 00:38.400
OK.

00:38.570 --> 00:40.920
So it is your.

00:40.990 --> 00:44.570
And live it's virus CNN.com.

00:45.170 --> 00:45.610
OK.

00:45.660 --> 00:49.420
And in this fight how and in the line of code.

00:49.600 --> 00:50.460
OK.

00:50.540 --> 00:53.930
Are obviously going to protect our server against different types of attack.

00:53.930 --> 00:54.530
OK.

00:54.770 --> 00:59.040
So let's talk about each core here and it's working.

00:59.060 --> 01:04.050
So the first block here you can see it's going to protect the server against spoofing attacks.

01:04.050 --> 01:11.420
OK then another of the protocols that were against IP spoofing attacks OK the last lesson we learned

01:11.450 --> 01:14.130
how to protect against spoofing.

01:14.210 --> 01:14.610
OK.

01:14.660 --> 01:19.630
So this is another way for protecting against IP spoofing attack.

01:20.030 --> 01:28.100
The next line is ignored ICMP block cost request means a hacker can always get some information.

01:28.250 --> 01:33.940
So VIGEN a block here the ping replied So keep this line going along the ping replies.

01:34.050 --> 01:39.070
OK so this line will protect against these kinds of attack.

01:39.140 --> 01:42.450
The next block is diciples source packet routing.

01:42.770 --> 01:50.270
So I would suspect that routing means it is a mechanism used by Internet protocol to get a packet from

01:50.370 --> 01:52.160
you so still destination.

01:52.490 --> 01:58.370
So what happens is a hacker kept in the back gate OK and he can get the information.

01:58.370 --> 02:05.390
The sensitive information like are led to the apology and by getting that possibly he can provide some

02:05.390 --> 02:06.910
damage to our system.

02:07.070 --> 02:15.720
OK so by adding these phone lines we can protect against these kinds of attacks hogi or Heiko Council

02:15.740 --> 02:17.990
bypass some security restriction.

02:18.040 --> 02:21.750
OK by getting to know this information OK.

02:22.190 --> 02:25.220
So the next block is ignore Sindhi.

02:25.280 --> 02:30.680
OK so ignoring the period that it's better for same reasons.

02:30.680 --> 02:38.810
The reason is that I said that basically is the part of the Cubists created by this the person rocking

02:38.820 --> 02:42.840
part of the network from the host choice.

02:42.860 --> 02:46.520
So what happens is hackers can easily get an opt in table.

02:46.520 --> 02:52.730
OK I'll take that out and he can send the traffic to his own choice so keep the incoming traffic to

02:52.730 --> 02:56.020
his own choice and in his fear he can damage it.

02:56.110 --> 03:01.430
We're in a different phase so we can block writing these lines.

03:01.480 --> 03:03.290
OK in this configuration.

03:03.290 --> 03:03.950
Fine.

03:04.170 --> 03:07.360
OK can the next Luckies thing attacks.

03:07.430 --> 03:11.540
Blocking does not work against syntax in similar attacks.

03:11.540 --> 03:18.390
What happens is an attacker since hundreds of thousands of messages to the server.

03:18.500 --> 03:21.890
So do do that what happens is our them gets full.

03:21.920 --> 03:28.030
OK so this software could get hang or get slower.

03:28.080 --> 03:32.760
So OK so that our performance is kicked down.

03:32.790 --> 03:41.060
OK so performance get down to this attack so we can easily block these kinds of Courtown Ed in these

03:41.100 --> 03:43.060
four lines of code here.

03:43.330 --> 03:49.310
OK the next block is logged my audience in lock Martyn's what happens.

03:49.400 --> 03:52.880
And attack could send the packets from fake IP.

03:53.030 --> 04:00.350
Or you can call it as the IP which is not present to Kamins the same IP addresses is reserved for experimental

04:00.350 --> 04:00.870
purposes.

04:00.890 --> 04:07.600
So in these types of contacts what happens is our server by the time it is used to by our server to

04:07.650 --> 04:14.900
process that packet and our silver band we get hysterical in an article since these kinds of packet

04:14.960 --> 04:22.940
are daemon burned with the gate just so we can easily block log my inspired software by adding these

04:22.940 --> 04:24.210
two lines of code.

04:24.710 --> 04:30.460
And the last one is ignoring data pings by using some software.

04:30.740 --> 04:38.600
Heckert can send hundreds of thousands of requests from different parts of the world from different

04:38.600 --> 04:39.440
computers.

04:39.490 --> 04:48.360
So we're OK and these things are caused by tick tick pings and that so were get down or get crushed.

04:48.450 --> 04:53.050
OK so we can protect those that were against the data attack.

04:53.240 --> 05:00.870
OK so in this way we can Hudner were not clear OK from all these kinds of possible attacks.
