Skip to content
This repository has been archived by the owner on Sep 27, 2023. It is now read-only.

Suggestion: if not fortify, monitor changes to packet filter firewall. #29

Open
geoff-nixon opened this issue Jul 10, 2020 · 0 comments

Comments

@geoff-nixon
Copy link

I'd like to strongly suggest that the pf settings be verified for tampering. It is extremely easy (like, by using 17.0.0.0/8 signed software and exporting a variable) to modify it. The socket/application firewall is deprecated (and I believe can be bypassed?) since the introduction of the packet filter.

@geoff-nixon geoff-nixon changed the title Suggestion: (at least) monitor, in not fortify, packet filter firewall. Suggestion: if not fortify, monitor changes to packet filter firewall. Jul 10, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant