Gentoo Archives: gentoo-security

From: Oliver Schad <o.schad@×××.de>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] iptables window of opportunity at startup
Date: Sat, 04 Feb 2006 17:30:03
Message-Id: 200602041822.40190.o.schad@web.de
In Reply to: [gentoo-security] iptables window of opportunity at startup by Jon Mitchell
1 Am Samstag, 4. Februar 2006 13:50 schrieb mir Jon Mitchell:
2 > The current behaviour of a default Gentoo install is to load iptables
3 > after the network has been initialised. Upon shutting down likewise
4 > iptables is shutdown then the network interface. This strikes me as
5 > presenting a window of opportunity when the computer is exposed
6 > without iptables, albeit a small one.
7 >
8 > Do people on this list think there is any value in re-arranging this
9 > order by default?
10
11 No this doesn't offers a hole, when no service is running and routing is
12 deactivated. So all services have to be started after iptables rules.
13 Same for routing.
14
15 Iptables doesn't have to protect the TCP/IP stack but a network behind
16 the host or services on that host.
17
18 Best regards
19 Oli
20 --
21 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] iptables window of opportunity at startup " Staffan Emrén " <staffan.emren@×××.se>
Re: [gentoo-security] iptables window of opportunity at startup Jon Mitchell <junk@×××××××.uk>