On Mon, 8 Sep 2003, PK Carlisle wrote:
> I am new to playing with Linux so I admit that I could very well be
> wrong about this...
>
> Looking through the docs for the Linux firewall, it seems that if you
> accept packets on, for example, port 80, then -any program- can
> communicate on port 80, you cannot limit which programs can
> communicate with the internet, so you could not automatically block
> spyware, etc., that is, you cannot automatically block any program
> not on a list approved to communicate with the internet.
You're right that Linux's firewall implementation (netfilter -
iptables/ipchains are just tools to configure it) doesn't have the facility
to block by process name. But it should be possible to use the --gid-owner
matching functionality, together with setting binaries SETGID to have
approximately the same effect.
There are tools such as <http://sourceforge.net/projects/fireflier> and
<http://www.stud.uni-hamburg.de/users/lennart/projects/fieryfilter/> which
presumably use this functionality to implement Windows-style "personal
firewalls".
Best Regards,
Alex.
--
Alex Butcher Brainbench MVP for Internet Security: www.brainbench.com
Bristol, UK Need reliable and secure network systems?
PGP/GnuPG ID:0x271fd950 <http://www.assursys.com/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.