| To: | netfilter@lists.netfilter.org |
|---|---|
| Subject: | will --cmd-owner ever return? |
| From: | vwf <vwf@vulkor.net> |
| Date: | Tue, 27 Mar 2007 20:45:26 +0200 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | netfilter-list1@securepoint.com |
| List-archive: | </pipermail/netfilter> |
| List-help: | <mailto:netfilter-request@lists.netfilter.org?subject=help> |
| List-id: | General discussion and user questions <netfilter.lists.netfilter.org> |
| List-post: | <mailto:netfilter@lists.netfilter.org> |
| List-subscribe: | <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe> |
| List-unsubscribe: | <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe> |
| Reply-to: | vwf <vwf@vulkor.net> |
| Sender: | netfilter-bounces@lists.netfilter.org |
| User-agent: | Mutt/1.5.13 (2006-08-11) |
Hello, Since kernel 2.6.15, command owner matching is gone (-m owner --cmd-owner). I consider this match vital for securing a workstation. Programs are calling home (including well known very free source ones), emails contain all kinds of tricks to report back (some of them I cannot delete unseen), some programs are simply too insecure to be alowed to connect to some server (e.g. media players), and often I simply want my workstation to be absolutely quiet (except when I specificly ask for something). How can I lock my workstation down on application level? Please tell me Netfilter can do this. Or can't it? |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Multi ISP router/firewall ..., Pierre JUHEN |
|---|---|
| Next by Date: | Re: will --cmd-owner ever return?, Tom Eastep |
| Previous by Thread: | [ipset] Minor non-blocking "sleep" bugs, Ismaël BALLO |
| Next by Thread: | Re: will --cmd-owner ever return?, Tom Eastep |
| Indexes: | [Date] [Thread] [Top] [All Lists] |