X-Recipient: archive-cygwin@delorie.com
X-SWARE-Spam-Status: No, hits=-0.6 required=5.0 	tests=BAYES_40,J_CHICKENPOX_55,RCVD_IN_DNSWL_LOW,SPF_PASS
X-Spam-Check-By: sourceware.org
Date: Tue, 30 Dec 2008 19:47:31 -1000 (HST)
From: Antonio Querubin <tony@lava.net>
To: Charles Wilson <cygwin@cwilson.fastmail.fm>
cc: Cygwin Mailing List <cygwin@cygwin.com>
Subject: Re: cygwin-1.7, sshd, tcpd, and IPv6/Vista
In-Reply-To: <495AAD1D.4080203@cwilson.fastmail.fm>
Message-ID: <Pine.BSI.4.64.0812301944300.10515@malasada.lava.net>
References: <495AAD1D.4080203@cwilson.fastmail.fm>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
X-IsSubscribed: yes
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
Precedence: bulk
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie.com@cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

On Tue, 30 Dec 2008, Charles Wilson wrote:

> So, the "allow" entries in hosts.allow are really only enabling access
> form the actual "127.0.0.1" aka "::1" machine -- that is, the actual
> local host.  They do not REALLY enable access from those bad guys that
> spybot maps to localhost.
>
> Can anybody think of an alternate explanation (perhaps this is a bug in
> cygwin-1.7's resolver code, or a bug I haven't spotted in tcpd?) Am I
> being too blase' about modifying hosts.allow as
>
> ALL : 127.0.0.1/32 : allow
> ALL : [::1]/128 : allow
> ALL : PARANOID : deny
> sshd: all
>
> or, am I right that doing so is perfectly safe even with a munged up
> hosts file -- and if so, should I modify the default hosts.allow shipped
> with tcp_wrappers?

It's perfecty valid.  FreeBSD's default /etc/hosts.allow is setup that 
way so you're in good company.


Antonio Querubin
whois:  AQ7-ARIN

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

