LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-18-2013, 08:17 PM   #1
MechaMorph
LQ Newbie
 
Registered: Feb 2013
Posts: 6

Rep: Reputation: Disabled
Can't figure out how to insert iptables rule first


Greetings,

I have an app for Android that leverages IPTABLES to block apps based on UID.

It works great with one exception on some devices using Android 4.x. When a user enables "Set Mobile Data Limit" on some devices the iptables for cellular data are negated.

How would I insert my rules to offset this?

pkts bytes target prot opt in out source destination
37 7848 costly_rmnet_sdio0 all -- any rmnet_sdio0 anywhere anywhere [goto]

I currently insert into the beginning of the chain and reapplying the rules doesn't change anything.

IPTABLES -I OUTPUT 1 -j droidwall

Here is the full output on a device that is affected by this issue.

root@android:/ # iptables --list OUTPUT --verbose
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
108 6758 all -- any !lo+ anywhere anywhere ! quota globalAlert: 2097152 bytes
37 7848 costly_rmnet_sdio0 all -- any rmnet_sdio0 anywhere anywhere [goto]
1321 85531 ACCEPT all -- any lo anywhere anywhere
39239 2701K all -- any any anywhere anywhere owner socket exists
273 21255 droidwall all -- any any anywhere anywhere

Any help is greatly appreciated!
Thanks in advance!
 
Old 02-19-2013, 03:51 AM   #2
wadhah102
LQ Newbie
 
Registered: Apr 2011
Location: Tunis, Tunisia
Distribution: Ubuntu/Debian/CentOS
Posts: 14

Rep: Reputation: 0
Hi,

i dont have android phone ^_^ but i know many thinks about SDK & NDK, so i think that this activate the quotation with the commande:
Quote:
quotaon
that's why the iptables for cellular data are negated.

for more information about quotaon

Best regards
 
Old 02-19-2013, 08:10 AM   #3
MechaMorph
LQ Newbie
 
Registered: Feb 2013
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wadhah102 View Post
Hi,

i dont have android phone ^_^ but i know many thinks about SDK & NDK, so i think that this activate the quotation with the commande:

that's why the iptables for cellular data are negated.

for more information about quotaon

Best regards
If I used quotas on my rules I would override the Mobile Data Limit rule thus breaking that functionality correct?

Can't I get my rules to insert before the quota so that the firewall is functional and the Mobile Data Limit is still functional as well?
 
Old 02-19-2013, 10:17 AM   #4
wadhah102
LQ Newbie
 
Registered: Apr 2011
Location: Tunis, Tunisia
Distribution: Ubuntu/Debian/CentOS
Posts: 14

Rep: Reputation: 0
Hi,

The
Quote:
Mobile Data Limit
use the quotation quotaon so when you activate this application the iptables for cellular data are negated

so i think you can use one of them the Mobile Data Limit/quoaton or iptables

Best Regards
 
Old 02-19-2013, 10:57 AM   #5
MechaMorph
LQ Newbie
 
Registered: Feb 2013
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wadhah102 View Post
Hi,

The use the quotation quotaon so when you activate this application the iptables for cellular data are negated

so i think you can use one of them the Mobile Data Limit/quoaton or iptables

Best Regards
That's a no go since quota is not in Android.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Need help, can't figure it out! (awk/insert every nth line) sc0rpi0n Programming 15 04-19-2012 10:29 AM
iptables: rule with RETURN target just after a rule with ACCEPT target Nerox Linux - Networking 6 09-04-2011 03:33 PM
iptables: one thing I can't figure. Sum1 Linux - Security 9 09-16-2009 12:02 PM
Fowarding using iptables - I can't figure it out anymore... lumkichi Linux - Networking 5 02-03-2009 04:33 PM
Can't figure out how to set up NAT/iptables is confusing rcx11 Linux - Networking 5 05-05-2007 05:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration