openwrt/package
Philip Prindeville de8b88ce17 firewall: add rule for traceroute support
Running your firewall's "wan" zone in REJECT zone (1) exposes the
presence of the router, (2) depending on the sophistication of
fingerprinting tools might identify the OS and release running on
the firewall which then identifies known vulnerabilities with it
and (3) perhaps most importantly of all, your firewall can be
used in a DDoS reflection attack with spoofed traffic generating
ICMP Unreachables or TCP RST's to overwhelm a victim or saturate
his link.

This rule, when enabled, allows traceroute to work even when the
default input policy of the firewall for the wan zone has been
set to DROP.

Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
2020-05-21 20:23:10 +02:00
..
base-files base-files: switch_to_ramfs: add nand-utils 2020-05-18 18:24:06 +02:00
boot ramips: Add support for Xiaomi Redmi Router AC2100 (RM2100) 2020-05-20 15:26:22 +02:00
devel perf: build with NO_LIBCAP=1 2020-04-26 21:20:47 +02:00
firmware layerscape: update ls-dpl to LSDK-20.04 2020-05-07 12:53:06 +02:00
kernel mac80211: Update to version 5.7-rc3-1 2020-05-21 14:39:34 +02:00
libs wolfssl: update to 4.4.0-stable 2020-05-20 17:03:45 +02:00
network firewall: add rule for traceroute support 2020-05-21 20:23:10 +02:00
system mtd: add linksys_bootcount for ramips 2020-05-17 18:43:19 +02:00
utils fuse: move package to packages feed 2020-05-20 18:59:46 +02:00
Makefile packages: apply usign padding workarounds to package indexes if needed 2019-08-07 07:15:07 +02:00