Go to file
Pawel Marczewski 63d8065e4f
firewall: drop INVALID state TCP packets
Packets detected as INVALID are ignored by NAT, so if they are not
dropped, packets with internal source IPs can leak to the outside
network.

See:

https://bugzilla.netfilter.org/show_bug.cgi?id=693
http://www.smythies.com/~doug/network/iptables_notes/

Fixes QubesOS/qubes-issues#5596.
2020-01-24 19:01:00 +01:00
archlinux Install qubes-rpc files in Archlinux 2019-10-21 23:00:51 +01:00
autostart-dropins Enable gnome settings daemon xsettings plugin 2018-01-12 05:44:54 +01:00
ci tests: add run-tests script, plug it into travis 2017-05-20 13:20:08 +02:00
debian version 4.1.7 2020-01-17 05:12:04 +01:00
doc Remove qrexec-agent related files 2019-04-08 18:22:38 +02:00
init Remove dead code 2019-07-05 20:35:31 +02:00
misc Merge remote-tracking branch 'origin/pr/207' 2020-01-24 01:53:33 +01:00
network firewall: drop INVALID state TCP packets 2020-01-24 19:01:00 +01:00
patches.debian Fix misleading error message on rootfs resize 2019-09-30 04:03:06 +02:00
pkgs archlinux: created build scripts 2013-04-17 01:22:32 +02:00
qubes-rpc Merge remote-tracking branch 'origin/pr/203' 2020-01-16 04:24:07 +01:00
qubesagent update_connected_ips: set iptables policy to drop while updating 2020-01-14 11:46:23 +01:00
rpm_spec Added "QubesIncoming" shortcut to Nautilus 2020-01-13 16:45:41 +01:00
test-packages tests: add run-tests script, plug it into travis 2017-05-20 13:20:08 +02:00
vm-init.d Merge branch 'remove-qrexec' 2019-06-06 23:20:11 +02:00
vm-systemd Fix typo 2020-01-16 14:12:01 -05:00
.coveragerc tests: add run-tests script, plug it into travis 2017-05-20 13:20:08 +02:00
.gitignore Update gitignore and make clean target 2018-04-20 16:27:26 +02:00
.travis.yml travis: switch to dom0 Fedora 31 2020-01-11 11:38:27 +01:00
debian-quilt debian: fix shellcheck warnings in debian packaging 2017-09-30 05:05:33 +02:00
LICENSE Added LICENSE 2010-04-05 21:21:27 +02:00
Makefile Merge remote-tracking branch 'origin/pr/188' 2019-10-21 00:45:47 +02:00
Makefile.builder Revert "Use sfdisk instead of parted to ..." on stretch and jessie 2019-02-24 05:15:04 +01:00
run-tests Load only test_* files when looking for tests (python) 2018-04-02 23:19:02 +02:00
series-debian-jessie-vm.conf Revert "Use sfdisk instead of parted to ..." on stretch and jessie 2019-02-24 05:15:04 +01:00
series-debian-stretch-vm.conf Revert "Use sfdisk instead of parted to ..." on stretch and jessie 2019-02-24 05:15:04 +01:00
series-debian-vm.conf Stop anacron from starting in Debian using existing constraint on cron 2017-02-05 23:36:27 +00:00
setup.py network: rewrite qubes-firewall daemon 2016-09-12 05:22:53 +02:00
version version 4.1.7 2020-01-17 05:12:04 +01:00