Nick Sayer 5b9c7d3e5b Fix some glaring insecurities in the prototype firewall configurations.
pass udp from any 53 to ${oip}

allows an attacker to access ANY local port by simply binding his local
side to 53. The state keeping mechanism is the correct way to allow DNS
replies to go back to their source.
2001-02-20 19:54:31 +00:00
..
2000-10-06 17:36:05 +00:00
2001-02-19 07:12:37 +00:00
2001-02-18 02:11:37 +00:00
1999-09-13 17:09:08 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-09-13 17:09:08 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
1999-09-13 17:09:08 +00:00
1999-08-27 23:37:10 +00:00
2000-12-26 20:55:18 +00:00
1999-08-27 23:37:10 +00:00
1999-08-27 23:37:10 +00:00
2000-11-01 13:30:24 +00:00
1999-08-27 23:37:10 +00:00
rpc
1999-08-27 23:37:10 +00:00
2000-11-13 20:47:18 +00:00
2000-04-27 21:58:46 +00:00
2000-08-25 08:56:28 +00:00