Gentoo Archives: gentoo-user

From: Meino.Cramer@×××.de
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Blocking certain sites the easy way ?
Date: Thu, 28 May 2015 06:44:34
Message-Id: 20150528064423.GF4276@solfire
In Reply to: Re: [gentoo-user] Blocking certain sites the easy way ? by Mick
1 Mick <michaelkintzios@×××××.com> [15-05-28 07:44]:
2 > On Thursday 28 May 2015 06:11:08 Meino.Cramer@×××.de wrote:
3 > > Hi,
4 > >
5 > > With wireshark I found, that firefox accesses sites on startup, from
6 > > which I dont know, for what reason this access is needed or whether
7 > > the NSA, CIA, FBI, BDN, MOSSAD (fill in what organisation you ever
8 > > suspect to do such things) has invaded my PC.
9 >
10 > It may none of the above, but FF and any addons checking what the latest
11 > version is of themselves, as well as the Google search on the default hope
12 > page doing a DNS query or some such.
13 >
14 >
15 > > I want to block such accesses for two reasons: First is ...hmmm...
16 > > to block that accesses...second is to find out what will not work
17 > > than.
18 > >
19 > > I dont want to install and configure a complete full blown firewalled
20 > > SEL-Linux thingy here and I dont want to reboot my Linux box for every
21 > > new site I added. I am looking for a simple solution, which I can use
22 > > without studying the history of TCP/IP and others... ;)))
23 > >
24 > > What can I use for this purpose?
25 >
26 > You could try an application layer filter[1], but I think it won't work
27 > insofar the connections you observed are probably using ports and protocols
28 > same as your day to day browsing activity. Therefore you will likely need to
29 > use iptables to block individual domains or IP addresses and then regularly
30 > add to the list when the servers your browser wants to contact change in that
31 > amorphous and reconfiguring cloud out there.
32 >
33 > You don't have to reboot your box when you change rules, but you'll need to
34 > reload iptables.
35 >
36 >
37 > [1] http://l7-filter.sourceforge.net/HOWTO-kernel
38 >
39 > --
40 > Regards,
41 > Mick
42
43 Hi Mick,
44
45 thanks for your help ! :)
46
47 What mechanism is recommended to be used to reinstall/initiate the
48 iptable rules while booting? Any Gentoo-ish? ;)
49
50 Best regard,
51 Meino

Replies

Subject Author
Re: [gentoo-user] Blocking certain sites the easy way ? Mick <michaelkintzios@×××××.com>