NetFilter
[Top] [All Lists]

will --cmd-owner ever return?

To: netfilter@lists.netfilter.org
Subject: will --cmd-owner ever return?
From: vwf <vwf@vulkor.net>
Date: Tue, 27 Mar 2007 20:45:26 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Reply-to: vwf <vwf@vulkor.net>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mutt/1.5.13 (2006-08-11)
Hello,

Since kernel 2.6.15, command owner matching is gone (-m owner
--cmd-owner). I consider this match vital for securing a workstation.
Programs are calling home (including well known very free source ones),
emails contain all kinds of tricks to report back (some of them I cannot
delete unseen), some programs are simply too insecure to be alowed to
connect to some server (e.g. media players), and often I simply want my
workstation to be absolutely quiet (except when I specificly ask for
something).

How can I lock my workstation down on application level?
Please tell me Netfilter can do this. Or can't it?




<Prev in Thread] Current Thread [Next in Thread>