Re: enabling tcpip_socket by default

From: Andrew Dunstan <andrew(at)dunslane(dot)net>
To: pgsql-hackers(at)postgresql(dot)org
Subject: Re: enabling tcpip_socket by default
Date: 2004-05-17 22:00:48
Message-ID: 40A93610.1010105@dunslane.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Greg Stark wrote:

>
>
>>Ah! Of course. That makes sense, and listening on 127.0.0.1 never
>>hurt anyone (except, of course, the tinfoil hat crowd nmapping
>>localhost in a frenzy...)
>>
>>
>
>Actually on many systems it was very possible to send packets to a machine
>with a source address of 127.0.0.1 even over external networks or through
>routers. Making an attack out of this on a TCP service would be difficult, but
>it has been done.
>
>Good OS distributions install network filters by default to refuse such
>packets, but lots of OSes still don't do this.
>
>
>

But what we listen to relates to the destination address of the packets,
not the source address ...

cheers

andrew

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Doug McNaught 2004-05-17 22:01:34 Re: enabling tcpip_socket by default
Previous Message Greg Stark 2004-05-17 21:53:39 Re: enabling tcpip_socket by default