Re: Default kernel network variables, sysctl, not secure enough.

2014-02-02 Thread Reco
Hi. On Sun, 02 Feb 2014 13:47:36 +1300 "C.T.F. Jansen" wrote: > Installed them and looked for man pages, nothing found, then through > /usr/share/doc again. This had a number of extra files in it that seemed > relevant but the variables set were not found as such. A look in > >/usr/share

Default kernel network variables, sysctl, not secure enough.

2014-02-01 Thread C.T.F. Jansen
Greetings, Did a security audit on Debian 7 using tiger and found some less than secure settings for network variables in the kernel. One of the variables flagged was net.ipv4.conf.all.rp_filter . This and the rest in this group can be set in /etc/sysctl.conf . T