"egress filter" on OSX?

James Burton jimb at burtcom.com
Wed Jan 21 12:24:33 PST 2004


A week ago, I installed SNORT on the iMac I use as a server, and the 
past two days I've been getting alerts of suspicious traffic 
""BAD-TRAFFIC loopback traffic"

A file referenced in the alert explains that this happens when someone 
spoofs an internal IP and uses it to snoop for exploitable ports.

The file also says that to combat this, one should employ an "egress 
filter." Does anyone know how to set this up on OSX? One would think 
that this would be built-in since it seems to be a common avenue of 
attack.

Jim



More information about the X-Unix mailing list