linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: James Turnbull <james@lovedthanlost.net>
To: luke@techfreak.org
Cc: linux-admin@vger.kernel.org
Subject: Re: SSH allow only form selected IP'
Date: Mon, 16 Aug 2004 21:23:49 +1000	[thread overview]
Message-ID: <41209945.40205@lovedthanlost.net> (raw)
In-Reply-To: <1216.66.189.78.234.1092581976.squirrel@srv01.scriptgods.com>

[-- Attachment #1: Type: text/plain, Size: 547 bytes --]

luke@techfreak.org wrote:

>I'm definitely not a firewall expert, but isn't it also possible to
>get around
>IPchains using IP spoofing? From what I know ipchains is only
>protected against spoofing by using source address verification.
>
>Or am I way off?
>
>Luke
>  
>
A little off. :)  Yes you can spoof iptables but not nearly as easily as 
hosts.allow can be spoofed.  Hosts.allow's verifications procedures are 
considerably less sophisticated than those of iptables.

Regards

James

P.S. Generally Ipchains has been replaced by Iptables. 

[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/x-pkcs7-signature, Size: 2801 bytes --]

  reply	other threads:[~2004-08-16 11:23 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-14 11:52 Re[2]: SSH allow only form selected IP' luke
2004-08-15 12:58 ` James Turnbull
2004-08-15 13:54   ` Re[2]: " Kev
2004-08-15 14:59   ` luke
2004-08-16 11:23     ` James Turnbull [this message]
2004-08-16 13:37       ` Re[2]: " Kev
2004-08-16 16:30         ` VPN question Tony Gogoi
2004-08-16 17:29           ` Adam Lang
2004-08-16 18:50             ` Tony Gogoi
2004-08-16 18:59               ` Adam Lang
2004-08-18 10:46         ` SSH allow only form selected IP' Stephen Samuel
  -- strict thread matches above, loose matches on Subject: below --
2004-08-14 10:34 Kev
2004-08-14 10:54 ` James Turnbull
2004-08-14 11:18   ` Re[2]: " Kev
2004-08-14 11:42     ` James Turnbull
2004-08-14 11:46     ` James Turnbull

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=41209945.40205@lovedthanlost.net \
    --to=james@lovedthanlost.net \
    --cc=linux-admin@vger.kernel.org \
    --cc=luke@techfreak.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).