Subject:
|
Re: review: Radeon 7000 for BrickDraw3D, low-end Mac
|
Newsgroups:
|
lugnet.off-topic.geek
|
Date:
|
Tue, 16 Apr 2002 18:12:49 GMT
|
Viewed:
|
314 times
|
| |
![Post a public reply to this message](/news/icon-reply.gif) | |
In article <Guo6u6.Mu4@lugnet.com>,
Larry Pieniazek <lpieniazek@mercator.com> wrote:
> How can it be filtering and forwarding if there are no processes running?
> And why wouldn't it shutdown all the way at some point?
It's something of a cheat; the world doesn't tend to consider the kernel
to be a process in and of itself, and with stuff like ipchains you can
effectively put all the firewall rules and functionality in the kernel.
So you still have a kernel running.
I personally consider something like LIDS to be a better solution--
Mandatory Access Control added on top of Unix. You can restrict, file
by file, access-- so, for example, you can set the log files to have
only "append only" access; you can't modify 'em except for adding to the
end. You can set it up so that any file you don't need append access to
for logging have _no_ writable access-- even by root. (Mandatory Access
Control is cool that way.) Shutting down processes that arent the kernel
gets you in a position where you have no logging and therefore no real
intrusion detection.
Of course, in the ideal world, you can't _have_ an intrusion to detect
a halted firewall, but I don't live in an ideal world...
-JDF
--
J.D. Forinash ,-.
jd@forinash.not ( <
The more you learn, the better your luck gets. `-'
|
|
Message has 1 Reply:
Message is in Reply To:
26 Messages in This Thread: ![review: Radeon 7000 for BrickDraw3D, low-end Mac -Erik Olson (11-Apr-02 to lugnet.off-topic.geek, lugnet.cad.dev.mac)](/news/x.gif) ![](/news/246.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Andrew Allan (11-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Don Heyse (11-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/68.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Don Heyse (11-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/246.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Dan Boger (11-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -John D. Forinash (15-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Dan Boger (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/246.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Larry Pieniazek (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Dan Boger (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Larry Pieniazek (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![You are here](/news/here.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Ross Crawford (17-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/x.gif) ![](/news/68.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -John D. Forinash (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Dan Boger (16-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -John D. Forinash (17-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -William R. Ward (17-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/246.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -John D. Forinash (17-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -William R. Ward (18-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/246.gif) ![Graphics cards on the PC (was some pansy mac stuff -Larry Pieniazek (18-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/x.gif) ![](/news/268.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -John D. Forinash (19-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -William R. Ward (20-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/x.gif) ![](/news/68.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Erik Olson (23-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/28.gif) ![](/news/x.gif) ![](/news/x.gif) ![](/news/68.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Matthew Miller (22-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Ancient and obscure hardware geekery (Was: Re: review: Radeon 7000 for BrickDraw3D, low-end Mac) -John D. Forinash (23-Apr-02 to lugnet.off-topic.geek)](/news/x.gif) ![](/news/46.gif) ![Re: Ancient and obscure hardware geekery (Was: Re: review: Radeon 7000 for BrickDraw3D, low-end Mac) -Matthew Miller (23-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
![](/news/x.gif) ![](/news/x.gif) ![](/news/68.gif) ![Re: review: Radeon 7000 for BrickDraw3D, low-end Mac -Andrew Allan (11-Apr-02 to lugnet.off-topic.geek)](/news/x.gif)
- Entire Thread on One Page:
- Nested:
All | Brief | Compact | Dots
Linear:
All | Brief | Compact
This Message and its Replies on One Page:
- Nested:
All | Brief | Compact | Dots
Linear:
All | Brief | Compact
|
|
|
|