From: John Haxby <john.haxby@oracle.com>
To: Mail List - Netfilter <netfilter@vger.kernel.org>
Subject: Re: Portsweep
Date: Wed, 24 Sep 2008 08:59:20 +0100 [thread overview]
Message-ID: <48D9F358.3020005@oracle.com> (raw)
In-Reply-To: <48D9534B.4080602@riverviewtech.net>
Grant Taylor wrote:
> On 09/23/08 01:51, bahamin takhtaei wrote:
>> Do you know How to use iptables against Portsweep attacks?
>
> There use to be a Port Scan Detection (psd) match extension that would
> help detecting this easier. I.e. did it look like a system was
> initiating a port scan, and if so, handle it accordingly (drop /
> reject / tar pit / etc.). I don't know what the current state of the
> psd match is, so you will have to find out.
FWIW, my Netgear DG834N has this in a chain called DOS:
SCAN all -- anywhere anywhere psd weight-threshold: 21 delay-threshold: 300 lo-ports-weight: 3 hi-ports-weight: 1
Netgear make their source available so you could try looking there.
jch
next prev parent reply other threads:[~2008-09-24 7:59 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-09-23 6:51 Portsweep bahamin takhtaei
2008-09-23 20:36 ` Portsweep Grant Taylor
2008-09-24 7:59 ` John Haxby [this message]
2008-09-24 13:55 ` Portsweep Grant Taylor
2008-09-24 8:24 ` Portsweep bahamin takhtaei
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48D9F358.3020005@oracle.com \
--to=john.haxby@oracle.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.