1 |
10/13/2005, "Giles Coochey" <giles.coochey@××××××××××××××××.com> |
2 |
napisa³(a): |
3 |
|
4 |
>Iptables is nice because it is at kernel level, if someone were to try |
5 |
>to hack it so that your Iptables commands were ignored then they would |
6 |
>need to be able to reboot the box, something that you would probably |
7 |
|
8 |
Do I understand correctly that you claim that to undo the iptables you |
9 |
need to reboot box ? Or maybe you claim something that you assume but do |
10 |
not tell (non-vanilla hardened systemem) ? |
11 |
|
12 |
>notice in a managed environment. |
13 |
> |
14 |
>Tcpd runs in userspace, so given root access is a lot easier to |
15 |
>compromise the executable. |
16 |
|
17 |
I don't get your point... If you give me root access - what's the |
18 |
difference in r00ting the box via fake iptables or tcpd ? |
19 |
|
20 |
Anyway comparing iptables with tcpd is rather useless, they seem to |
21 |
perform the same job but they fight on different fronts. |
22 |
|
23 |
> |
24 |
>NOTICE: This e-mail message and all attachments |
25 |
>transmitted with it may contain legally privileged and |
26 |
>confidential information intended solely for the use of |
27 |
>the addressee. If the reader of this message is not the |
28 |
|
29 |
Well, pretty much anybody can subs to this list. |
30 |
|
31 |
>intended recipient, you are hereby notified that any |
32 |
>reading, dissemination, distribution, copying, or other |
33 |
>use of this message or its attachments, hyperlinks, or |
34 |
>any other files of any kind is strictly prohibited. If you |
35 |
>have received this message in error, please notify the |
36 |
>sender immediately by telephone (+44-1865-265500) or by |
37 |
>a reply to this electronic mail message and delete this |
38 |
>message and all copies and backups thereof. |
39 |
|
40 |
And how can you enforce that ? |
41 |
|
42 |
Excuse me but I think such notices are complete waste of space & time, |
43 |
while attached to public mailing list. Please do not attach them, thank |
44 |
you! |
45 |
|
46 |
-- |
47 |
gentoo-security@g.o mailing list |