the_fireball I have fucking failed | mikala a écrit :
grsecurity 2.1.6 est sorti .
d'ailleurs je viens de remarquer un truc que je n'avais pas vu auparavant
+stealth networking support
+CONFIG_IP_NF_MATCH_STEALTH
+ Enabling this option will drop all syn packets coming to unserved tcp
+ ports as well as all packets coming to unserved udp ports. If you
+ are using your system to route any type of packets (ie. via NAT)
+ you should put this module at the end of your ruleset, since it will + drop packets that aren't going to ports that are listening on your + machine itself, it doesn't take into account that the packet might be + destined for someone on your internal network if you're using NAT for + instance.
+
+ If you want to compile it as a module, say M here and read
+ Documentation/modules.txt. If unsure, say `N'.
+
|
|
à activer apres avoir lu la doc sur comment on met quelque chose à la fin d'un ruleset (et qu'est-ce qu'un ruleset)  ---------------
Two thousand years of misery, of torture in my name, hypocrisy made paramount, paranoia the law, my name is called religion, sadistic, sacred whore.
|