Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Eric Leblond <eric@inl.fr>
To: "R. DuFresne" <dufresne@sysinfo.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: [Announce] Nulog 1.1.0 is available
Date: Sun, 03 Jul 2005 23:43:15 +0200	[thread overview]
Message-ID: <1120426995.8058.14.camel@localhost.localdomain> (raw)
In-Reply-To: <Pine.LNX.4.60.0507011532460.16419@darkstar.sysinfo.com>

Le vendredi 01 juillet 2005 à 15:34 -0400, R. DuFresne a écrit :
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> 
> considering the history of php, and many php applications and their 
> bi-weekly appearance in the various sec lists for newly discovered vulns, 
> how afe is this application and would one want to place it on or near 
> their main security device?

This application exists since some years now and we have proceed to some
code audits and have carefully checked user entries to avoid SQL
injection or other problems.

The other point is that this application has not to be available for
evryone has it contains private information. Thus, it can be protected
from "bad people" by authentication or other mean. To be simple, access
has to be restricted to admins.

An other point is that permissions on the MySQL database should and can
be carefully set to have only read-only permission on the table
containing the ulogd/NuFW logs. This restricted permissions can assure
that the logged datas can not be corrupted. Futhermore, in the case of
an Ulogd installation, the logged packets can be duplicated in syslog,
thus any hypothetic datas corruption is armless.

Finally, as ulogd can log on a database running on a separate host, your
firewall is safe as there is no server running on it. 

BR,
-- 
Eric Leblond <eric@inl.fr>



  reply	other threads:[~2005-07-03 21:43 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-06-30 12:59 [Announce] Nulog 1.1.0 is available Eric Leblond
2005-07-01 19:34 ` R. DuFresne
2005-07-03 21:43   ` Eric Leblond [this message]
2005-07-04 17:07     ` matt
  -- strict thread matches above, loose matches on Subject: below --
2005-07-18 15:23 Eric Leblond

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1120426995.8058.14.camel@localhost.localdomain \
    --to=eric@inl.fr \
    --cc=dufresne@sysinfo.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox