Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Gavin" <gavin@raha.com>
To: "Gaël Le Mignot" <kilobug@freesurf.fr>
Cc: netfilter@lists.netfilter.org
Subject: Re: nmap
Date: Wed, 23 Oct 2002 15:15:58 +0300	[thread overview]
Message-ID: <031501c27a8d$f2070940$583a29c4@ghome> (raw)
In-Reply-To: plopm33cqxs6qt.fsf@drizzt.dyndns.org

>  >> But... what do you want to do by filtering OUTPUT ? Sure, you can drop
>  > INVALID
>  >> packets, filter floods, stop packets coming from root and so on, but
if
>  > you
>  >> want to allow normal internet activity from the box, you have to allow
NEW
>  >> connections on OUTPUT to any host/port...
>
>  > There's always a (good) chance that someone will comprimise the machine
and
>  > use it to DDOS, scan, spam etc - filtering output to allow only what
you
>  > need for normal usage (dns, web, ping etc) makes it less useful as a
hacked
>  > box.
>
> If you allow users to mail, you allow them to spm. If you allow users to
send
> requests on tcp 80, you allow them to participe in a DDOS, and so on.
> There is no real way to sort  out "clean" and "bad" actions at the
firewall
> level... The only thing you can do is using the 'limit' macth to prevent
> some kinds of DoS. And allowing only some ports can be very limitating
> for users, since some web servers listenon other ports, they may want to
use
> cvs pserver (and you didn't think to allow 3128) and so on...


Would I be right in thinking that the OUTPUT chain only filters traffic
originating from the firewall box itself, and that any traffic coming from
your clients would fall into the FORWARD chain?  If that is the case, then
filtering OUTPUT would have no effect on your users' ability to surf, mail
etc, but only on the firewall box's ability to generate traffic.

Gavin


> Gael Le Mignot "Kilobug" - kilobug@freesurf.fr - http://kilobug.free.fr
> GSM         : 06.71.47.18.22 (in France)   ICQ UIN   : 7299959
> Fingerprint : 1F2C 9804 7505 79DF 95E6 7323 B66B F67B 7103 C5DA
>
> Member of HurdFr: http://hurdfr.org - The GNU Hurd: http://hurd.gnu.org
>
>




  reply	other threads:[~2002-10-23 12:15 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-22  5:20 PPTP Question Rommy Taslim
2002-10-22 15:42 ` nmap antonio
2002-10-22 18:25   ` nmap Gaël Le Mignot
2002-10-22 19:12     ` nmap antonio
2002-10-22 21:05       ` nmap Gaël Le Mignot
2002-10-22 22:35         ` nmap antonio
2002-10-23  7:35           ` nmap Gaël Le Mignot
2002-10-23  9:06             ` nmap Gavin
2002-10-23 12:02               ` nmap Gaël Le Mignot
2002-10-23 12:15                 ` Gavin [this message]
2002-10-23 15:25                   ` nmap Antony Stone
2002-10-22 18:31   ` nmap Antony Stone
2002-10-22 22:38     ` nmap hellbreak
2002-10-22 23:25   ` nmap Nick Drage
  -- strict thread matches above, loose matches on Subject: below --
2002-10-22 19:19 nmap Antonio Paulo Salgado Forster
2002-10-22 20:46 nmap Andy Wood
2002-10-22 21:11 nmap Antonio Paulo Salgado Forster
2002-10-23  5:35 nmap zeus

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='031501c27a8d$f2070940$583a29c4@ghome' \
    --to=gavin@raha.com \
    --cc=kilobug@freesurf.fr \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox