Re: Can a daemon listen only on some interfaces?
At 08.12.2001, Mark Lanett wrote:
> Postfix is configurable as to which interfaces it listens to. So are samba,
> courier-imap, apache. The only problem is that each one has its own
> completely different kind of configuration file.
Sorry, but AFAIK that is not true!
You can configure on which ip address to listen and this ip address is
bound to an interface. On linux all local ip addresses are reachable
over all local network interfaces - thats the problem. If an attacker is
able to route packets to an internal ip address over your externel
interface, he can reach an internel bound service.