Full Disclosure mailing list archives

RE: Application level firewall


From: Andriy Bilous <Andriy.Bilous () sabre-merlin de>
Date: Fri, 17 Oct 2003 14:40:52 +0200

iptables does it. read through man iptables carefully.

Andriy Bilous 
-system administration- 
CCNA, CCNP Certified
dcs DILLON COMMUNICATION SYSTEMS GmbH & Co. KG 
Weidestraße 122 b 
D-22083 Hamburg 
phone +49 40 27 83 82 184 
fax   +49 40 27 83 82 999 
mailto:andriy.bilous () sabre-merlin de
http://www.sabre-merlin.de


-----Original Message-----
From: Jason Freidman [mailto:jason.full-disclosure () compnski com]
Sent: Friday, October 17, 2003 2:02 PM
To: Full-Disclosure () lists netsys com
Subject: [Full-disclosure] Application level firewall


Is there any sort of application level firewall for linux?  Something
like Zone alarm where you can trust an application?  I think that
openBSD has something that allows you to choose which system calls a
program can run.

The idea would be to restrict a bind call and connect call 
using kernel
modules unless the program is in a config file.  It would 
make it easier
(i would think) to lockdown a computer for outgoing 
connections as well
as add a new layer of security.

-- 
Jason Freidman <jason.full-disclosure () compnski com>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: