@ryanc@infosec.exchange I learned something cursed when researching the transition of these things, which is that the linux kernel can load both iptables and nftables rules at the same time, on the same machine, and nftables rules take precedence but fall back to iptables afterwards
imagine trying to debug a system that you thought was using iptables but actually has a secret nftables rule inserted before iptables even sees the packet.. all the iptables rules would be totally correct, because the filtering happens earlier on 🙃
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
CyberFrog (froge@social.glitched.systems)'s status on Thursday, 29-Aug-2024 17:39:25 JSTCyberFrog