Re: Filtering module on OSI level 7?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Friday 2008-05-02 15:15, Benedikt Gollatz wrote:

>On Friday 02 May 2008 14:20:44 you wrote:
>> I would nevertheless prefer something similar to LittleSnitch
>> (http://www.obdev.at/products/littlesnitch/index.html) on OS X or to
>> ZoneAlarm on Windows.
>
>Why? Filtering traffic by application (which is different from filtering 
>traffic based on the application layer) doesn't add anything to security. If 
>you don't trust an application to behave correctly, you also cannot trust it 
>not to use other applications via IPC to connect to the Internet.

But you can catch the fact that it does use IPC. There is
tuxguardian.sourceforge.net, but it has not really be touched since 2.6.16.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux