BUG: Audiogalaxy Rule colludes with HTTP

Paolo Costa <[email protected]>
Newsgroups gmane.network.guarddog
Message-ID <[email protected]>
Hi,

I tried to disable the outgoing HTTP traffic by un-selecting the
corresponding box in the protocol pane. Unfortunately, however, after
applying these mods, I was still able to surf the web as if nothing was
happened.

After some debugging, I finally discovered that this unexpected behavior
is due to the concomitant rule of AudioGalaxy. Indeed, as specified in
rc.firewall, this rules leaves connection to port 80 open because of the
need of connecting to audiogalaxy server.

IMHO, this represents a serious security issue, since this violates the
rules on HTTP, which should have priority over this.

Similarly, I noticed that by enabling outgoing NFS protocol, *all* ports
> 1024 are automatically open. Honestly, I don't remember whether NFS
does require all ports open but still there must be some control to
avoid the concurrent rule is violated this way.

Paolo




-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.