immortalwrt/package
Philip Prindeville afc9f6ec52
firewall: add rule for traceroute support
Running your firewall's "wan" zone in REJECT zone (1) exposes the
presence of the router, (2) depending on the sophistication of
fingerprinting tools might identify the OS and release running on
the firewall which then identifies known vulnerabilities with it
and (3) perhaps most importantly of all, your firewall can be
used in a DDoS reflection attack with spoofed traffic generating
ICMP Unreachables or TCP RST's to overwhelm a victim or saturate
his link.

This rule, when enabled, allows traceroute to work even when the
default input policy of the firewall for the wan zone has been
set to DROP.

Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
2020-05-23 19:17:18 +08:00
..
base-files lantiq: sync official source code 2020-04-25 18:29:43 +08:00
boot mediatek: add uboot 2020-05-05 11:56:01 +08:00
ctcgfw luci-app-serverchan: sync with upstream source 2020-05-23 18:57:16 +08:00
devel gdb: Fix build on AArch64 (#4619) 2020-05-18 09:37:14 +08:00
firmware Merge Lean's source 2020-05-13 17:50:08 +08:00
kernel kernel: kmod-ptp-qoriq: Package kernel object file 2020-05-21 12:01:46 +08:00
lean default-settings: fix replace feeds version 2020-05-23 18:53:55 +08:00
libs wolfssl: update to 4.4.0-stable 2020-05-21 12:02:44 +08:00
lienol luci-theme-*: bump jQuery to v3.5.0 2020-05-05 11:36:18 +08:00
network firewall: add rule for traceroute support 2020-05-23 19:17:18 +08:00
ntlf9t AdGuardHome: use official build 2020-05-16 19:15:43 +08:00
system opkg: update to latest Git HEAD 2020-05-10 12:06:43 +08:00
utils ugps: nmea: fix time comparision 2020-04-30 12:00:25 +08:00
zxlhhyccc verysync: add architecture dependence 2020-04-23 18:17:38 +08:00
Makefile sync build script for OpenWrt 19.07 2020-02-21 02:41:00 +08:00