1 Mar 2005 01:20
Re: new REBOOT target
Max Kellermann <max <at> duempel.org>
2005-03-01 00:20:58 GMT
2005-03-01 00:20:58 GMT
On 2005/02/28 10:41, Wang Jian <lark <at> linux.net.cn> wrote: > Beside my laziness, the --passphrase is an error-proof mechanism per > se. Let's assume some one wants to use -j REBOOT, but he doesn't > specified a good enough match, just '-p icmp', then boom ;) In this > sense, the --passphrase is not match, but part of target. (my first reply to you didn't get to the list, maybe a mailman failure?) Now what about an error proof admin? ;) Sorry, I don't think this is a good argument, don't try to find an excuse for writing a dangerous rule (and for writing such a netfilter "design violation"). If an admin is brave enough to compile REBOOT into the kernel and write "-j REBOOT" somewhere, it's his own fault he didn't implement the correct match. Someone with root access should know better. REBOOT should ... reboot! Not match the protocol or a certain pass phrase. Max
RSS Feed