Re: restrict implicit binding to interfaces
- From: Maxwell Lol <nospam@xxxxxxxxxxx>
- Date: Thu, 30 Oct 2008 08:08:24 -0400
David Schwartz <davids@xxxxxxxxxxxxx> writes:
On Oct 29, 5:54 pm, Rick Jones <rick.jon...@xxxxxx> wrote:
While "Linux" is very much not such a stack on a "Strong End-System
Model" system binding to a given IP address is pretty much the same
thing since the traffic to that IP will only be accepted on that
interface.
Umm, no!!! That would make building a router virtually impossible.
Traffic to any IP assigned to the machine will, and must, be accepted
regardless of what interface it arrives on.
DS
Sounds like a real security risk to me. That says I can send packets
to a router/firewall with the destination being the inside address,
and it will respond.
.
- Follow-Ups:
- Re: restrict implicit binding to interfaces
- From: David Schwartz
- Re: restrict implicit binding to interfaces
- References:
- restrict implicit binding to interfaces
- From: Wolfgang Draxinger
- Re: restrict implicit binding to interfaces
- From: David Schwartz
- Re: restrict implicit binding to interfaces
- From: Rick Jones
- Re: restrict implicit binding to interfaces
- From: David Schwartz
- restrict implicit binding to interfaces
- Prev by Date: Re: BIND -- can't register nameserver
- Next by Date: Re: restrict implicit binding to interfaces
- Previous by thread: Re: restrict implicit binding to interfaces
- Next by thread: Re: restrict implicit binding to interfaces
- Index(es):
Relevant Pages
|