delorie.com/archives/browse.cgi | search |
X-Recipient: | archive-cygwin AT delorie DOT com |
X-SWARE-Spam-Status: | No, hits=-0.6 required=5.0 tests=BAYES_40,J_CHICKENPOX_55,RCVD_IN_DNSWL_LOW,SPF_PASS |
X-Spam-Check-By: | sourceware.org |
Date: | Tue, 30 Dec 2008 19:47:31 -1000 (HST) |
From: | Antonio Querubin <tony AT lava DOT net> |
To: | Charles Wilson <cygwin AT cwilson DOT fastmail DOT fm> |
cc: | Cygwin Mailing List <cygwin AT cygwin DOT com> |
Subject: | Re: cygwin-1.7, sshd, tcpd, and IPv6/Vista |
In-Reply-To: | <495AAD1D.4080203@cwilson.fastmail.fm> |
Message-ID: | <Pine.BSI.4.64.0812301944300.10515@malasada.lava.net> |
References: | <495AAD1D DOT 4080203 AT cwilson DOT fastmail DOT fm> |
MIME-Version: | 1.0 |
X-IsSubscribed: | yes |
Mailing-List: | contact cygwin-help AT cygwin DOT com; run by ezmlm |
List-Id: | <cygwin.cygwin.com> |
List-Unsubscribe: | <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com> |
List-Subscribe: | <mailto:cygwin-subscribe AT cygwin DOT com> |
List-Archive: | <http://sourceware.org/ml/cygwin/> |
List-Post: | <mailto:cygwin AT cygwin DOT com> |
List-Help: | <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs> |
Sender: | cygwin-owner AT cygwin DOT com |
Mail-Followup-To: | cygwin AT cygwin DOT com |
Delivered-To: | mailing list cygwin AT cygwin DOT com |
On Tue, 30 Dec 2008, Charles Wilson wrote: > So, the "allow" entries in hosts.allow are really only enabling access > form the actual "127.0.0.1" aka "::1" machine -- that is, the actual > local host. They do not REALLY enable access from those bad guys that > spybot maps to localhost. > > Can anybody think of an alternate explanation (perhaps this is a bug in > cygwin-1.7's resolver code, or a bug I haven't spotted in tcpd?) Am I > being too blase' about modifying hosts.allow as > > ALL : 127.0.0.1/32 : allow > ALL : [::1]/128 : allow > ALL : PARANOID : deny > sshd: all > > or, am I right that doing so is perfectly safe even with a munged up > hosts file -- and if so, should I modify the default hosts.allow shipped > with tcp_wrappers? It's perfecty valid. FreeBSD's default /etc/hosts.allow is setup that way so you're in good company. Antonio Querubin whois: AQ7-ARIN -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/
webmaster | delorie software privacy |
Copyright © 2019 by DJ Delorie | Updated Jul 2019 |