Leopard's Firewall "Flawed"

The place for technology related posts.

Moderator: Moderators

Post Reply
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Leopard's Firewall "Flawed"

Post by complacent »

More /. goodness found hmah.

Ok, no biggie for us n3rdz, right?


Btw, If vi-ing or pico-ing an ipfw-based firewall is beyond your comfort level - try waterroof. It's a pretty decent GUI frontend for teh configz. wewt.


ZOMG INnArWEBZ!!!!!1
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Post by Sabre »

After looking at their article... they are making mountains out of mole hills in some areas (not all though). The way the Mac firewall works is by allowing any network program that is started to automatically start servicing requests. So if you start services (like they did in the first part of the article), it will allow them. Windows does the same thing...

Sounds like Apple isn't updating the Mac firewall GUI with the latest rule sets. Easy enough to fix.

Now this part is a different story:
A number of peculiarities emerged in the course of testing. A newly booted MacBook refused time synchronization - only to permit it a few moments later for no apparent reason without any changes to the security settings having been made. Further, it is not clear at what point Mac OS X starts which services, or how it decides which of these should be accessible and which should not.
This really isn't good and I have to wonder what changed. I REALLY wish they had done a "ipfw show" before and after running all of these commands.

You are right though, we (geeks in general) won't have to worry about this, but some of these problems should be addresses for regular home users.
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
chicken n waffles
Moderator
Posts: 6314
Joined: Wed Oct 19, 2005 1:15 am
Location: Alexandria

Post by chicken n waffles »

i understood a bit of that, but for the most part,

Image


ps - aapl... flawed software? z0mg NO WAI!!1
-Ben
Image
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

ipfw makes baby jesus cry. :(
2004 impreza outback
1964 beetle
User avatar
Libra Monkee
Moderator
Posts: 6478
Joined: Wed Mar 29, 2006 11:04 pm
Location: The Ether
Contact:

Post by Libra Monkee »

I'm just hoping that Leopard has better WPA support because using my wireless on Tiger SUCKS!
Image

Libra Monkee- "Helping DCAWD meet its Equal Opportunity requirement since 2006."
User avatar
Phibs
DCAWD Groupie
Posts: 1197
Joined: Tue Dec 21, 2004 7:00 pm
Location: Sterling, VA
Contact:

Post by Phibs »

Before I have a seizure, plz change avatar k thx!
Bryan
2012 WRX 5-Door Limited
User avatar
Libra Monkee
Moderator
Posts: 6478
Joined: Wed Mar 29, 2006 11:04 pm
Location: The Ether
Contact:

Post by Libra Monkee »

No, I think you deserve a seizure. :twisted:
Image

Libra Monkee- "Helping DCAWD meet its Equal Opportunity requirement since 2006."
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Post by Sabre »

schvin wrote:ipfw makes baby jesus cry. :(
:shock: :lol2: Come on, it's not THAT bad... Hell, throw dummynet on it and you've got a rate limiting firewall :)
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Post by complacent »

Sabre wrote:
schvin wrote:ipfw makes baby jesus cry. :(
:shock: :lol2: Come on, it's not THAT bad... Hell, throw dummynet on it and you've got a rate limiting firewall :)
I was thinking the same! It's not that bad! ;)

What would yonder security guru (teh schvin, talkin' at ya) recommend if ipfw is makin' teh jeebus cry?
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Post by Sabre »

complacent wrote:
Sabre wrote:
schvin wrote:ipfw makes baby jesus cry. :(
:shock: :lol2: Come on, it's not THAT bad... Hell, throw dummynet on it and you've got a rate limiting firewall :)
I was thinking the same! It's not that bad! ;)

What would yonder security guru (teh schvin, talkin' at ya) recommend if ipfw is makin' teh jeebus cry?
If anyone says IPChains I will promptly punch them in the gonads... or cuch if need be. :twisted:
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
User avatar
Libra Monkee
Moderator
Posts: 6478
Joined: Wed Mar 29, 2006 11:04 pm
Location: The Ether
Contact:

Post by Libra Monkee »

Alright, alright... back to Leopard's flaws. I have to agree with this article in thanking the Mac geeks, er... fools, no... early adopters (don't hurt me Colin :oops:) for the getting these bugs out of the way now before the rest of us drop our hard-earned duckets on this OS.

Beyond the normal growing pains of adapting to a new OS, and the aforementioned firewall deal, there seems to be no Java 6 support in Leopard which has developers up in arms.

/. posting
Associated c|net art.
Image

Libra Monkee- "Helping DCAWD meet its Equal Opportunity requirement since 2006."
User avatar
Mr Kleen
DCAWD Founding Member
Posts: 15034
Joined: Mon Apr 18, 2005 6:46 pm
Location: Wiesbaden.DE

Post by Mr Kleen »

i wish the new macbook pros weren't so damn expensive. i'd like to experiment with the dark side (light side?) :?
User avatar
Phibs
DCAWD Groupie
Posts: 1197
Joined: Tue Dec 21, 2004 7:00 pm
Location: Sterling, VA
Contact:

Post by Phibs »

Libra Monkee wrote:Alright, alright... back to Leopard's flaws. I have to agree with this article in thanking the Mac geeks, er... fools, no... early adopters (don't hurt me Colin :oops:) for the getting these bugs out of the way now before the rest of us drop our hard-earned duckets on this OS.

Beyond the normal growing pains of adapting to a new OS, and the aforementioned firewall deal, there seems to be no Java 6 support in Leopard which has developers up in arms.

/. posting
Associated c|net art.
Congrats!

I believe I had java6 running on mine, but not 100% sure. I will say though for the record, I hate java :)
Bryan
2012 WRX 5-Door Limited
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

Sabre wrote:
complacent wrote:
Sabre wrote: :shock: :lol2: Come on, it's not THAT bad... Hell, throw dummynet on it and you've got a rate limiting firewall :)
I was thinking the same! It's not that bad! ;)

What would yonder security guru (teh schvin, talkin' at ya) recommend if ipfw is makin' teh jeebus cry?
If anyone says IPChains I will promptly punch them in the gonads... or cuch if need be. :twisted:
oh, not a chance :) that punching would definitely be deserved!

oh, and pf ftw.

pf (and altq/etc) have been rolled out of openbsd to netbsd and freebsd so far, so i can't imagine it's much of a stretch to get it on the osx. my 2 cents.
2004 impreza outback
1964 beetle
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Post by Sabre »

schvin wrote: oh, not a chance :) that punching would definitely be deserved!

oh, and pf ftw.

pf (and altq/etc) have been rolled out of openbsd to netbsd and freebsd so far, so i can't imagine it's much of a stretch to get it on the osx. my 2 cents.
Ok, we can still be friends ;) PF should be fairly easy to get over to OSX me thinks.
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

Sabre wrote:
schvin wrote: oh, not a chance :) that punching would definitely be deserved!

oh, and pf ftw.

pf (and altq/etc) have been rolled out of openbsd to netbsd and freebsd so far, so i can't imagine it's much of a stretch to get it on the osx. my 2 cents.
Ok, we can still be friends ;) PF should be fairly easy to get over to OSX me thinks.
:) +1
2004 impreza outback
1964 beetle
Post Reply