Gentoo Archives: gentoo-security

From: Jon Mitchell <junk@×××××××.uk>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] iptables window of opportunity at startup
Date: Sun, 05 Feb 2006 08:29:29
Message-Id: 1139127849.9183.11.camel@hornbeam.arboretum
In Reply to: Re: [gentoo-security] iptables window of opportunity at startup by Oliver Schad
1 On Sat, 2006-02-04 at 18:22 +0100, Oliver Schad wrote:
2 > Am Samstag, 4. Februar 2006 13:50 schrieb mir Jon Mitchell:
3 > > The current behaviour of a default Gentoo install is to load
4 iptables
5 > > after the network has been initialised. Upon shutting down likewise
6 > > iptables is shutdown then the network interface. This strikes me as
7 > > presenting a window of opportunity when the computer is exposed
8 > > without iptables, albeit a small one.
9 > >
10 > > Do people on this list think there is any value in re-arranging this
11 > > order by default?
12 >
13 > No this doesn't offers a hole, when no service is running and routing
14 is
15 > deactivated. So all services have to be started after iptables rules.
16 > Same for routing.
17
18 But this isn't quite what happens by default. Starting up I seem to get
19 the network, then http-replicator, then iptables. Shutting down is
20 worse: First iptables is turned off, then ntpd, sshd, http-replicator,
21 "unmounting network file systems", then the network. So if there were a
22 problem in these services they would be exposed.
23
24 How do you control the order that programs are shutdown in gentoo?
25
26 > Iptables doesn't have to protect the TCP/IP stack but a network
27 behind
28 > the host or services on that host.
29
30 Could the network behind the host also be exposed in this small window?
31 If you had a firewall machine (two interfaces and packet forwarding)
32 without its firewall?
33
34 > Best regards
35 > Oli
36
37 Thanks,
38 Jon
39
40
41
42 --
43 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] iptables window of opportunity at startup Tobias Klausmann <klausman@××××××××××××.de>
Re: [gentoo-security] iptables window of opportunity at startup Oliver Schad <oliver.schad@×××××××××××.com>
Re: [gentoo-security] iptables window of opportunity at startup Oliver Schad <oliver.schad@×××××××××××.com>