From: bash <0x62ash@gmail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: help me (nfcan: addressed to exclusive sender for this address)
Date: Wed, 29 Mar 2006 21:54:58 +0400 [thread overview]
Message-ID: <20060329215458.bf063d97.0x62ash@gmail.com> (raw)
In-Reply-To: <20060329042226.GK7855@salty>
On Tue, 28 Mar 2006 23:22:26 -0500
Jim Laurino <nfcan.x.jimlaur@dfgh.net> wrote:
> I am not an expert on this,
> but for what it is worth:
>
> Perhaps the rules used to detect
> and limit brute force ssh attacks
> could be adapted to your need.
You are talking about "recent" module... I don't know how I can use
it in my situation....
> Does NetLook have a predictable pattern?
Forget about NetLook...
My criteria for blocking is:
if rate of SYN packages from ONE source IP is greater then 3packets/sec
=> then block this IP
And i can't add rule "-m limit" per all source IP in my net,
because my net is big (~255^3)....
> You can find out about the ssh blocking rules
> if you search the archives for 'brute force'.
>
> Hope that helps.
--
Biomechanica Artificial Sabotage Humanoid
next prev parent reply other threads:[~2006-03-29 17:54 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-03-29 0:19 help me bash
2006-03-29 1:50 ` John A. Sullivan III
2006-03-29 3:29 ` bash
2006-03-29 4:22 ` help me (nfcan: addressed to exclusive sender for this address) Jim Laurino
2006-03-29 17:54 ` bash [this message]
2006-03-29 18:28 ` Rob Sterenborg
2006-03-29 19:14 ` bash
2006-03-30 5:45 ` Rob Sterenborg
2006-03-30 15:58 ` bash
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060329215458.bf063d97.0x62ash@gmail.com \
--to=0x62ash@gmail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.