Complete.Org: Mailing Lists: Archives: freeciv-dev: January 2003:
[Freeciv-Dev] Re: new connect dialog (ver 4) (PR#1911)
Home

[Freeciv-Dev] Re: new connect dialog (ver 4) (PR#1911)

[Top] [All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index] [Thread Index]
To: kaufman@xxxxxxxxxxxxxxxxxxxxxx
Cc: freeciv-dev@xxxxxxxxxxx
Subject: [Freeciv-Dev] Re: new connect dialog (ver 4) (PR#1911)
From: "ChrisK@xxxxxxxx via RT" <rt@xxxxxxxxxxxxxx>
Date: Sun, 19 Jan 2003 07:59:39 -0800
Reply-to: rt@xxxxxxxxxxxxxx

On Sun, Jan 19, 2003 at 07:11:12AM -0800, Andreas Kemnade via RT wrote:
> 
> > Why isn't it sufficient to bind the server only to the loopback interface,
> > e.g. with the recently posted freeciv-bindip-patch?
> > 
> Unix is a multi user operating system. Another user on the same machine can 
> get
> the hack accesslevel even when the server is only binded to the loopback
> interface.

Oh yes. But the common gamer will be the only user of the machine.

BTW does the loopback bind work on windows, too?

The possibility of connects to a civserver listening on 0.0.0.0 is still
a risk IMHO. With Mike's approach there is the possibility of a DoS attack, 
probably (not tested).

> Greetings
> Andreas Kemnade

Christian

-- 
Christian Knoke     * * *      http://www.enter.de/~c.knoke/
* * * * * * * * *  Ceterum censeo Microsoft esse dividendum.



[Prev in Thread] Current Thread [Next in Thread]