1 |
> >So why many people and security guides still suggest the use of tcpd |
2 |
> >over simple iptables rules? |
3 |
> |
4 |
> Not sure, maybe this pros |
5 |
> - if you forget to start your iptables script your ports are open |
6 |
> - you can check with 'PARANOID' whether hostname and ip record match |
7 |
> |
8 |
|
9 |
This could end up being a very interesting thread. |
10 |
|
11 |
Iptables is nice because it is at kernel level, if someone were to try |
12 |
to hack it so that your Iptables commands were ignored then they would |
13 |
need to be able to reboot the box, something that you would probably |
14 |
notice in a managed environment. |
15 |
|
16 |
Tcpd runs in userspace, so given root access is a lot easier to |
17 |
compromise the executable. |
18 |
|
19 |
Just my 2c |
20 |
|
21 |
|
22 |
|
23 |
|
24 |
NOTICE: This e-mail message and all attachments |
25 |
transmitted with it may contain legally privileged and |
26 |
confidential information intended solely for the use of |
27 |
the addressee. If the reader of this message is not the |
28 |
intended recipient, you are hereby notified that any |
29 |
reading, dissemination, distribution, copying, or other |
30 |
use of this message or its attachments, hyperlinks, or |
31 |
any other files of any kind is strictly prohibited. If you |
32 |
have received this message in error, please notify the |
33 |
sender immediately by telephone (+44-1865-265500) or by |
34 |
a reply to this electronic mail message and delete this |
35 |
message and all copies and backups thereof. |
36 |
|
37 |
|
38 |
-- |
39 |
gentoo-security@g.o mailing list |