"egress filter" on OSX?
James Burton
jimb at burtcom.com
Wed Jan 21 12:24:33 PST 2004
A week ago, I installed SNORT on the iMac I use as a server, and the
past two days I've been getting alerts of suspicious traffic
""BAD-TRAFFIC loopback traffic"
A file referenced in the alert explains that this happens when someone
spoofs an internal IP and uses it to snoop for exploitable ports.
The file also says that to combat this, one should employ an "egress
filter." Does anyone know how to set this up on OSX? One would think
that this would be built-in since it seems to be a common avenue of
attack.
Jim
More information about the X-Unix
mailing list