Re: Priviledged ports and masquerade

Mark Wooding (mdw@excessus.demon.co.uk)
3 Apr 1998 18:08:21 -0000


Jason Venner <jason@idiom.com> writes:

> I can't rlogin/rsh through a masq server, the priviledged source port
> gets mapped out of the priviledged range by the masquerade server.
>
> Is this worth fixing?

I'd say that this would be a really bad idea. It'd let any old
unprotected machine being masqueraded by a Linux machine to spoof a
connection from a privileged port on a trusted host. That seems like a
bad idea to me.

Admittedly, doing authentication based on privileged source ports is
stupid anyway, but there's no sense in reducing poor security to no
security at all.

-- 
[mdw]

`Don't be too proud of this technological terror you've constructed.' -- Darth Vader

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu