Gentoo Logo
Gentoo Spaceship

Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
To: "gentoo-security" <gentoo-security@g.o>
From: "Łukasz C. Jokiel" <Lukasz.Jokiel@...>
Subject: RE: hosts.{allow,deny} vs. iptables.
Date: Thu, 13 Oct 2005 21:17:40 +0200
10/13/2005, "Giles Coochey" <giles.coochey@...>

>Iptables is nice because it is at kernel level, if someone were to try
>to hack it so that your Iptables commands were ignored then they would
>need to be able to reboot the box, something that you would probably

Do I understand correctly that you claim that to undo the iptables you
need to reboot box ? Or maybe you claim something that you assume but do
not tell (non-vanilla hardened systemem) ?

>notice in a managed environment.
>Tcpd runs in userspace, so given root access is a lot easier to
>compromise the executable.

I don't get your point... If you give me root access - what's the
difference in r00ting the box via fake iptables or tcpd ? 

Anyway comparing iptables with tcpd is rather useless, they seem to
perform the same job but they fight on different fronts.

>NOTICE: This e-mail message and all attachments
>transmitted with it may contain legally privileged and
>confidential information intended solely for the use of
>the addressee. If the reader of this message is not the

Well, pretty much anybody can subs to this list. 

>intended recipient, you are hereby notified that any
>reading, dissemination, distribution, copying, or other
>use of this message or its attachments, hyperlinks, or
>any other files of any kind is strictly prohibited. If you
>have received this message in error, please notify the
>sender immediately by telephone (+44-1865-265500) or by
>a reply to this electronic mail message and delete this
>message and all copies and backups thereof.

And how can you enforce that ?

Excuse me but I think such notices are complete waste of space & time,
while attached to public mailing list. Please do not attach them, thank

gentoo-security@g.o mailing list

prelude-lml and log_prefix_regex
-- Chris
RE: hosts.{allow,deny} vs. iptables.
-- Giles Coochey
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
RE: hosts.{allow,deny} vs. iptables.
Next by thread:
prelude-lml and log_prefix_regex
Previous by date:
Re: hosts.{allow,deny} vs. iptables.
Next by date:
prelude-lml and log_prefix_regex

Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.