Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 23 Jan 1996 12:10:15 -0800 (PST)
From:      Nathan Lawson <nlawson@statler.csc.calpoly.edu>
To:        pete@sms.fi (Petri Helenius)
Cc:        security@freebsd.org
Subject:   Re: Ownership of files/tcp_wrappers port
Message-ID:  <199601232010.MAA11051@statler.csc.calpoly.edu>
In-Reply-To: <199601231004.MAA17990@silver.sms.fi> from "Petri Helenius" at Jan 23, 96 12:04:45 pm

next in thread | previous in thread | raw e-mail | index | archive | help
> Paul Traina writes:
>  > 
>  > I totally and completely disagree.  I do not want to be bound by your
>  > idea of what's proper for the core part of the system.  That's why we
>  > have a generic source distribution and you can personalize your system
>  > to your hearts content.
>  > 
>  > Read:  I will wish seriously bad karma on anyone who unilaterally bloats
>  >        out the system with the wrapper code.  There is NO good reason to
>  >        make it anything other than a port -- which makes it OPTIONAL to
>  >        install and easy to track 3rd party changes.
> 
> I couldn't agree more. Many places do have adequate firewalling procedures
> already in place and wrappers would do only more administrative overhead
> with no additional security.

And even more places do not have a firewall.  Do you want to put a label on
FreeBSD that says "Warning:  do not connect to Internet without a firewall"?
Of course, a firewall is a good first step, but there have been many ways to
circumvent packet-filtering routers, and some interesting attacks over 
application level gateways.  Personally, I'd like to know when Bob over in
Accounting telnets to my machine.  Or perhaps small ISP's that can't afford
a firewall.

I suggested that tcp_wrappers be installed in such a way as to minimize the
administrative overhead.  Compile it without ident and paranoid logging, and
don't put anything in /etc/hosts.deny except some sample, commented-out,
denies.  That way, all you get originally is increased logging, and you can
add the RFC931 and PARANOID options to the /etc/hosts.allow files _without_
recompiling (if you should desire).

-- 
Nate Lawson   \Yeah, I was dreaming through the 'howzlife', yawning, car black, 
Owner:         \when she told me 'mad and meaningless as ever...' and a song 
Cal Poly State  \came on the radio like a cemetery rhyme for a million crying 
University       \corpses in their tragedy of respectable existence.  - BR



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199601232010.MAA11051>