iptables and apt-get

> Instead of having one "-m state" rule Brad has a separate one for each
> service.  I have followed his lead without quite knowing just what is
> gained.  Maybe it limits what an intruder can do if he does get into the
> system.

I don't know if this is really necessary since a connection should only
be assigned the status ESTABLISHED by the kernel if it has really been
established; since all "initiating" packets (e.g. sync packets for TCP,
UDP with destination port 53 (domain)) should be carefully considered
anyway, it should be sufficient to set up explicite rules (i.e. addresses,
protocols, port numbers) there.  Imho, specifying these parameters also for
ESTABLISHED and RELATED packets can only add security to buggy kernels
(as it was the case with 2.4.3 and ftp).  Could anyone comment, please?

