From owner-freebsd-bugs@FreeBSD.ORG Tue Feb 5 14:40:03 2008 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D25E916A417 for ; Tue, 5 Feb 2008 14:40:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id BE71213C4E5 for ; Tue, 5 Feb 2008 14:40:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id m15Ee3Ft057190 for ; Tue, 5 Feb 2008 14:40:03 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id m15Ee3w0057189; Tue, 5 Feb 2008 14:40:03 GMT (envelope-from gnats) Date: Tue, 5 Feb 2008 14:40:03 GMT Message-Id: <200802051440.m15Ee3w0057189@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: "Andrey V. Elsukov" Cc: Subject: Re: kern/120290: ipfw jump rules X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: "Andrey V. Elsukov" List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 05 Feb 2008 14:40:03 -0000 The following reply was made to PR kern/120290; it has been noted by GNATS. From: "Andrey V. Elsukov" To: Marius Nistor Cc: FreeBSD-gnats-submit@FreeBSD.org Subject: Re: kern/120290: ipfw jump rules Date: Tue, 05 Feb 2008 17:11:02 +0300 Marius Nistor wrote: > [11:09:54 root@localhost ~]# ipfw show > 10164 0 0 allow ip from 193.64.7.151 to any uid net > 10165 21 5166 allow ip from any to 193.64.7.151 > 10166 23 1213 allow tcp from 193.64.7.151 10000-65535,21,22,25,80,110,113,443 to any > 10167 0 0 deny ip from 193.64.7.151 to any > 65535 989179 91977108 allow ip from any to any > [11:09:56 root@localhost ~]# > so rule 10164 and 10167 not used > i tryed 10166 allow tcp from 193.64.7.151 > 10000-65535,21,22,25,80,110,113,443 to any uid net ... but the ip is go > on internet without oidentd support Do you have any processes which deal with TCP/UDP with user's "net" credentials? -- WBR, Andrey V. Elsukov