From owner-freebsd-security Tue Jan 30 17:43:12 2001 Delivered-To: freebsd-security@freebsd.org Received: from h-209-91-79-2.gen.cadvision.com (h-209-91-79-2.gen.cadvision.com [209.91.79.2]) by hub.freebsd.org (Postfix) with ESMTP id DBF1F37B503 for ; Tue, 30 Jan 2001 17:42:55 -0800 (PST) Received: from cirp.org (localhost [127.0.0.1]) by h-209-91-79-2.gen.cadvision.com (8.9.3/8.9.3) with ESMTP id SAA15008 for ; Tue, 30 Jan 2001 18:42:51 -0700 (MST) (envelope-from gtf@cirp.org) Message-Id: <200101310142.SAA15008@h-209-91-79-2.gen.cadvision.com> Date: Tue, 30 Jan 2001 18:42:50 -0700 (MST) From: "Geoffrey T. Falk" Subject: Re: nfsd lacks support for tcp_wrapper To: freebsd-security@FreeBSD.org In-Reply-To: MIME-Version: 1.0 Content-Type: TEXT/plain; CHARSET=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On 31 Jan, Gerald Pfeifer wrote: > Unless we completely missed something, nfsd does lack support for > tcp_wrapper, doesn't it? > > As NFS is a rather critical security-wize this seems like a big omission. IP filters are always better than TCP wrappers. NFS should only be used behind a good firewall anyways. If you are paranoid about IP and DNS spoofing on the local network, don't use plain NFS... Geoffrey To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message