![]() |
#16 | |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Quote:
You do not have to write that ruleset table yourself, in fact it is rarely written by hand. There is an iptables command option to write it correctly, in the format that matches the version/implementation of iptables that is being used. Note: These are Busybox based systems - which may or may not have the for-real iptables command installed rather than using the Busybox version. You really need to check which version (Busybox minimum implementation or Real, full implementation). The ruleset for iptables is a declarative programming language - Never, ever, quote only a sub-set of the commands present. The above quote is either (incorrectly) hand-written or only a sub-set of the commands present. A Kindle may have at least three interface devices - 3G, Wifi, and USBnet. When you include an interface name in a rule, it applies to only that interface. As an example: If you want the quoted rules above to apply to all interfaces (regardless of how many) then do not include the interface limitation ("-i <interface name>"). As Hawhill points out, "drop" and "accept" are two of the (several) terminal targets - - - So if you "drop" everything on "-i wlan0" then that is the end of the life of those packets, they are dead on the floor, never to be seen or heard from again. As Hawhill points out, the distinction of "source" and "destination" is reversed in the above example. As the O.P. points out, the above snippet was never tried (because it can not possibly work as described/intended). In addition to only being applied to one of the three network interfaces, as written above - - - It will probably be only minutes (or a few days) before some crafty kid learns how to rename an interface so that it no longer matches any of the interface names mentioned in this snippet. Translation: Nice try but useless as presented. |
|
![]() |
![]() |
![]() |
#17 | ||
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 164
Karma: 164969
Join Date: Dec 2011
Device: Palm IIIx, (iPhone|Kindle) Touch
|
Quote:
Quote:
![]() I've updated my post with rules that allow private IPs and drops anything else for all interfaces. |
||
![]() |
![]() |
![]() |
#18 | |||||
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 164
Karma: 164969
Join Date: Dec 2011
Device: Palm IIIx, (iPhone|Kindle) Touch
|
Quote:
Quote:
Quote:
But I actually forgot the 3G interface. I always forget that one, because I don't have a KT with 3G and IMO it's more useful to Amazon than for the user. Quote:
Quote:
|
|||||
![]() |
![]() |
![]() |
#19 | |
Going Viral
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 17,212
Karma: 18210809
Join Date: Feb 2012
Location: Central Texas
Device: No K1, PW2, KV, KOA
|
Quote:
A "child proof" e-book reader. ![]() Yeah, right! The place to insert the rules is into the Kid, not the Kindle. As others here have already written. |
|
![]() |
![]() |
![]() |
#20 | |
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 164
Karma: 164969
Join Date: Dec 2011
Device: Palm IIIx, (iPhone|Kindle) Touch
|
Quote:
![]() |
|
![]() |
![]() |
![]() |
Tags |
disable ads, disable brower, disable store, disable wifi, putty |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Kindle Touch, Sony PRS-T1 and new Pocketbook Pro 622 Touch | Raindrop | Which one should I buy? | 13 | 12-31-2012 06:22 AM |
Kindle Touch, Nook Touch or Kobo Touch? | tron_1970 | Which one should I buy? | 33 | 05-01-2012 12:15 PM |
Torn: Nook Simple Touch, Kindle Touch, Basic Kindle | dblb48 | Which one should I buy? | 12 | 12-13-2011 02:34 PM |
ConsumerReport: E-book readers: Nook Simple Touch tops Kindle Touch | afv011 | Barnes & Noble NOOK | 4 | 11-22-2011 03:39 PM |
Kindle 3, Nook Simple Touch, Kobo Touch and Libra Pro Touch | jbcohen | Which one should I buy? | 4 | 06-18-2011 07:58 PM |