3 ms·
Just have sane firewall rules and you are good. E.g. if I install openssh-server and it auto starts, it doesn't make it out of my machine because my nftables do
by JackeJR 1y ago
Just have sane firewall rules and you are good. E.g. if I install openssh-server and it auto starts, it doesn't make it out of my machine because my nftables does not allow inbound on port 22. It's just knowing the default behaviour and adjusting your practices for it.
- teo_zero 1y agoAren't firewall rules part of the "configuration" the OP talked about?
- mjochim 1y agoNo, because you can install and configure the firewall before you install package X. (without knowing anything about X, your firewall defaults can just prevent X from doing anything) But you can't (easily) configure package X itself before you install it; and after you install it, it runs immediately so you only get to configure it after the first run.
- johnisgood 1y agoThat is a workaround for a ridiculous issue.
- rbanffy 1y agoA sane firewall won't protect you from privilege escalation from a local attacker. While unlikely, this is one more breach that could be exploited.
- bayindirh 1y agoDebian bundles AppArmor profiles for most services. This will prevent an attacker from accessing outside the perimeter drawn by the AppArmor profile.
- account42 1y agoThis is the "you're holding it wrong" response to a clear design issue.