From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 971C4138296 for ; Sat, 5 Jan 2013 03:27:40 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id D7AAD21C01F; Sat, 5 Jan 2013 03:27:24 +0000 (UTC) Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 2623421C004 for ; Sat, 5 Jan 2013 03:26:11 +0000 (UTC) Received: by mail-oa0-f44.google.com with SMTP id n5so15761020oag.3 for ; Fri, 04 Jan 2013 19:26:11 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; bh=ELSxx6j4XGjvCFdNDyrh17x4ze0XXb+JSGn1iuDJ+gk=; b=AOpl6rZBeh3gHAsdSLc7YFVtOmGDeUSlvT/yzx5YNGbrluGAcXUQlwRJU2Hv/NdXDP fVfl4q7H5fQmsaXl9xvSpi7H4qIcPIrDyZtxbNX1YT1geq+dPDkZIMAEEpoxc3cvBJOl m1n9GGww1RldjzF5J0FDUrDvX1RhCZFz9sshp0eJGZ2sAAtCjY8prrekE2r2ZKKhFjOn aj/WRMj3/zS0l3r03A3GoAdOo9QlZQbEtbpBfvJ0Iw61f67Gjm+aQsPClAtb0PGrz4jJ YBDLLceUeH7CKKUumzy5oWv3kB0HzEtaoFJpbFH0rTtvxx032u45qGdXcXlhr3yJq0bx rduA== Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 Received: by 10.182.240.41 with SMTP id vx9mr35083387obc.10.1357356371222; Fri, 04 Jan 2013 19:26:11 -0800 (PST) Received: by 10.76.20.243 with HTTP; Fri, 4 Jan 2013 19:26:10 -0800 (PST) Received: by 10.76.20.243 with HTTP; Fri, 4 Jan 2013 19:26:10 -0800 (PST) In-Reply-To: <20130105012949.GA17261@waltdnes.org> References: <50DBA7D0.4060800@orlitzky.com> <87zk0zivjk.fsf@einstein.gmurray.org.uk> <20121227231150.GA9864@waltdnes.org> <50DCDEAF.9020002@orlitzky.com> <20121228035937.GA2949@waltdnes.org> <50DD370F.4070509@orlitzky.com> <20121231032150.GA2032@waltdnes.org> <50E509FA.3060204@orlitzky.com> <20130104201702.GA16813@waltdnes.org> <20130105012949.GA17261@waltdnes.org> Date: Fri, 4 Jan 2013 22:26:10 -0500 Message-ID: Subject: Re: [gentoo-user] IPTABLES syntax change? From: Michael Mol To: gentoo-user@lists.gentoo.org Content-Type: multipart/alternative; boundary=14dae93b58e657205f04d2822883 X-Archives-Salt: e8581cb6-81a2-49ad-aca6-d200af774d1b X-Archives-Hash: 4d233183c83c757a10d415a0c0137881 --14dae93b58e657205f04d2822883 Content-Type: text/plain; charset=UTF-8 On Jan 4, 2013 8:33 PM, "Walter Dnes" wrote: > > On Fri, Jan 04, 2013 at 03:27:59PM -0500, Michael Mol wrote > > On Fri, Jan 4, 2013 at 3:17 PM, Walter Dnes wrote: > > > > > > The mere fact that you haven't manually typed in... > > > http://www.facebook.com/blah_blah_blah does not mean you're not > > > connecting to it. > > > > But all that's above layer 3, since it's an HTTP redirect, or a page > > transclusion which necessitates a new GET request. Michael's point > > stands. > > And I want to make sure that new GET request is blocked coming and > going. > > -- > Walter Dnes > I don't run "desktop environments"; I run useful applications > And it will, for the simple reason that outbound psckets are dropped, so inbound packets are nevrr valid. That was Michael's point. --14dae93b58e657205f04d2822883 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable


On Jan 4, 2013 8:33 PM, "Walter Dnes" <waltdnes@waltdnes.org> wrote:
>
> On Fri, Jan 04, 2013 at 03:27:59PM -0500, Michael Mol wrote
> > On Fri, Jan 4, 2013 at 3:17 PM, Walter Dnes <waltdnes@waltdnes.org> wrote:
> > >
> > > =C2=A0 The mere fact that you haven't manually typed in.= ..
> > > http://ww= w.facebook.com/blah_blah_blah does not mean you're not
> > > connecting to it.
> >
> > But all that's above layer 3, since it's an HTTP redirect= , or a page
> > transclusion which necessitates a new GET request. Michael's = point
> > stands.
>
> =C2=A0 And I want to make sure that new GET request is blocked coming = and
> going.
>
> --
> Walter Dnes <waltdnes@walt= dnes.org>
> I don't run "desktop environments"; I run useful applica= tions
>

And it will, for the simple reason that outbound psckets are dropped, so= inbound packets are nevrr valid. That was Michael's point.

--14dae93b58e657205f04d2822883--