2 ms·
I looked into the source code, it uses /proc/net/ip_tables_names to find the tables And that tbh doesn't seem very reliable, see what happened on a laptop whic
by kirab 9y ago
I looked into the source code, it uses /proc/net/ip_tables_names to find the tables
And that tbh doesn't seem very reliable, see what happened on a laptop which does not use iptables:
$ cat /proc/net/ip_tables_names
cat: /proc/net/ip_tables_names: No such file or directory
$ iptables -L
[...]
$ cat /proc/net/ip_tables_names
filter
$ iptables -t nat -L
[...]
$ cat /proc/net/ip_tables_names
nat
filter
This seems to only show loaded/active iptables tables. Which means that a table may exist but unless it is loaded you will not see it. But of course in our scenario the CIA would have activated some rules, so this table should appear there. Unless the CIA was also able to hide the table from that file, which may well be possible, since the table was added via a root kernel module...