|
|||||||||||
|
Re: Why not have firewall rules by default?
From: Florian Weimer <fw(at)deneb.enyo.de>
Date: Mon Jan 28 2008 - 12:43:27 EST
> On Wed, Jan 23, 2008 at 11:22:41PM +0100, Florian Weimer wrote: Where is this described in Policy? > Please check out section 3.6 of the "Securing Debian Manual". IIRC: portmap is typically not bound to the loopback interface. It's mostly used for fam, I think, so this should really be feasible. (But the localhost restriction patches for Sun RPC are broken anyway, AFIACS.) There are other systems where the web server listens on localhost only (if you explicitly install it, which you still need to do). Given that, I don't see that Debian follows a restrictive policy in this area, contrary to what you suggested. This isn't necessarily a bad thing, though. Received on Mon Jan 28 13:06:04 2008 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:31 EDT |
||||||||||
|
|||||||||||