BUG: Audiogalaxy Rule colludes with HTTP
Paolo Costa <[email protected]>
| Newsgroups | gmane.network.guarddog |
|---|---|
| Message-ID | <[email protected]> |
Hi, I tried to disable the outgoing HTTP traffic by un-selecting the corresponding box in the protocol pane. Unfortunately, however, after applying these mods, I was still able to surf the web as if nothing was happened. After some debugging, I finally discovered that this unexpected behavior is due to the concomitant rule of AudioGalaxy. Indeed, as specified in rc.firewall, this rules leaves connection to port 80 open because of the need of connecting to audiogalaxy server. IMHO, this represents a serious security issue, since this violates the rules on HTTP, which should have priority over this. Similarly, I noticed that by enabling outgoing NFS protocol, *all* ports > 1024 are automatically open. Honestly, I don't remember whether NFS does require all ports open but still there must be some control to avoid the concurrent rule is violated this way. Paolo ------------------------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/