4 ms·
You can use the owner extension: https://www.frozentux.net/iptables-tutorial/iptables-tutorial.html#OWNERMATCH https://www.frozentux.net/iptables-tutorial/iptab
by notalaser 9y ago
You can use the owner extension: https://www.frozentux.net/iptables-tutorial/iptables-tutorial.html#OWNERMATCH https://www.frozentux.net/iptables-tutorial/iptables-tutoria... , which can filter based on the PID of the process which created the packets.
But what we generally do is, you know, not run plugins that phone home :).
Edit: I just looked on a Linux machine - things have changed a little. That used to be my go-to document for iptables, which is why I referred you to it. You probably want to consult something more up-to-date.
In any case: iptables can do filtering based on who created the packets.
Even later edit: it probably goes without saying, but just in case -- this solves only half the problem, because it can only identify the process based on its PID. This makes it pretty trivial to overcome PID-based rules. The usual solution, of course, was to filter based on UID and run the program under a separate account.
I don't know if this got solved in the meantime, I haven't used iptables in a while now.