niXforums Forum Index
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   PreferencesPreferences   Log in to check your private messagesLog in to check your private messages   Log inLog in 
·  nixdoc.net ·  man pages ·  Linux HOWTOs ·  FreeBSD Tips ·  Forums
navigation Forum index » *nix » Linux » security
iptables TARPIT
Post new topic   Reply to topic Page 1 of 1 [2 Posts] View previous topic :: View next topic
Author Message
Ertugrul Soeylemez
*nix forums Guru Wannabe


Joined: 28 Oct 2005
Posts: 126

PostPosted: Sun Jun 25, 2006 7:06 am    Post subject: Re: iptables TARPIT Reply with quote

"ElCuervo" <cuervo73@wanadoo.es> (06-06-24 19:09:25):

Quote:
I have some iptables POM extensions ompiled into my 2.4.32 kernel
including TARPIT. And, I have crafted some rules to tarpit some
persistent IP's. But, this only works for TCP traffic.. how does one
slow down the pervasive unwanted UDP and ICMP traffic?

By not replying at all. Those protocols are not connection-oriented, so
you couldn't freeze scanners much, anyway. By the way, don't forget
that each frozen TARPIT connection actually uses resources on your
system. I don't think that it allows DoS attacks, but for older
systems, this may be a stability problem. I wouldn't use it for now,
and instead just keep DROP-ing unwanted packets. There is some reason
for the TARPIT target not to be in the stable releases.


Regards,
E.S.
Back to top
ElCuervo
*nix forums beginner


Joined: 25 Jun 2006
Posts: 1

PostPosted: Sun Jun 25, 2006 2:09 am    Post subject: iptables TARPIT Reply with quote

I have some iptables POM extensions ompiled into my 2.4.32 kernel
including TARPIT. And, I have crafted some rules to tarpit some
persistent IP's. But, this only works for TCP traffic.. how does one
slow down the pervasive unwanted UDP and ICMP traffic?

cuervo
Back to top
Google

Back to top
Display posts from previous:   
Post new topic   Reply to topic Page 1 of 1 [2 Posts] View previous topic :: View next topic
The time now is Fri Nov 21, 2008 4:19 am | All times are GMT
navigation Forum index » *nix » Linux » security
Jump to:  

Similar Topics
Topic Author Forum Replies Last Post
No new posts IPtables front end Stephen Allen Debian 13 Thu Jul 20, 2006 1:30 pm
No new posts Local forwarding with "iptables" gives "invalid arguments" newsfuzzy@geekmail.de networking 0 Wed Jul 19, 2006 2:47 pm
No new posts Iptables and kernel 2.6.17 phelp needed Chavdar Videff Debian 8 Wed Jul 19, 2006 6:30 am
No new posts iptables: How to specify multiple address bolero92@yahoo.com networking 2 Mon Jul 10, 2006 9:16 am
No new posts problem with active ftp and iptables lelle networking 4 Sun Jul 09, 2006 9:25 am

Bad Credit Loan | Mortgage | Credit Cards | Buy Anything On eBay | Loans
Copyright © 2004-2005 DeniX Solutions SRL
 
Other DeniX Solutions sites: Unix/Linux blog |  electronics forum |  medicine forum |  science forum | 
Privacy Policy


Powered by phpBB © 2001, 2005 phpBB Group
[ Time: 0.2712s ][ Queries: 20 (0.1768s) ][ GZIP on - Debug on ]