Re: [Security-Discuss] kernel

Dieter Schütze <dieter-ZpcFK/w3DkEX+nLd/[email protected]> Mon, 08 May 2006 15:47:02 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
I think the securest way is to run another kernel without sctp modul
activation.

Dieter

Luiz Fernando N. Capitulino schrieb:
> On Mon, 8 May 2006 10:04:54 -0300
> "Luiz Fernando N. Capitulino" <[email protected]> wrote:
>
> |  In the meanwhile, unload the SCTP conntrack module:
> | 
> | # rmmod ip_conntrack_proto_sctp
> | 
> |  and also:
> | 
> | # rmmod ipt_sctp
>
>  Urgh, now I have no sure whether it's really a workaround. I think
> netfilter will load that modules automatically when SCTP packets
> are received.
>
>  It's a good try anyway.
>
> PS: I'm checking whether there's a sysctl to unset it.
>
>   


-- 
Dieter Schütze
dieter-ZpcFK/w3DkEX+nLd/[email protected]
http://www.schuetze.homelinux.org

-----------------------------------
| Linux Tag 2006 in Wiesbaden vom |
| 03.05.2006 bis 06.05.2006       |
-----------------------------------

____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________