Re: abusing the fr_{st,nat}putent routines for transparent proxies

This is a discussion on Re: abusing the fr_{st,nat}putent routines for transparent proxies within the IPFilter forums, part of the System Security and Security Related category; In some email I received from Ryan Beasley, sie wrote: > From a, erm, "policy" perspective, is there ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-28-2003
Darren Reed
 
Posts: n/a
Default Re: abusing the fr_{st,nat}putent routines for transparent proxies

In some email I received from Ryan Beasley, sie wrote:
> From a, erm, "policy" perspective, is there any reason I should
> avoid using the fr_{st,nat}putent routines from a transparent proxy?
> I've modified 4.0a source to perform some add'l basic checks
> (incrementing the wildcard counter, associating entries w/ timeout
> queues, etc.) on the incoming entries before insertion and am running
> without problems so far. Doing it this way just seems much nicer
> than inserting "keep state" and IP NAT rules.
>
> Anyone have any ideas / suggestions?


Couple of pointers...

The routines that implement the "put" ioctl expect to be copying data
from userspace, so you'll need to account for that.

Otherwise, I can't see why not.

Darren
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:34 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0