iptables bug using dhcpd3 on debian sarge 2.6.8

richard hauswald staenker at rhcs.de
Thu Mar 10 09:10:25 CET 2005


Patrick McHardy wrote:

>
> ISC DHCP uses AF_PACKET sockets on Linux by default, which receive
> packets before iptables. There are some compile-time options to make it
> use normal UDP sockets.
>
> Regards
> Patrick
>
Thanks for that tip. But is this good or bad? I mean if i where a trojan 
programmer, couldn't i use these AF_PACKET sockets to code an iptables 
passing trojan?
I'm not good programming networkstuff, so excuse my simple question.

Regards
Richard Hauswald



More information about the netfilter-devel mailing list