* excellent rule archive
@ 2003-12-22 12:37 Chris Brenton
0 siblings, 0 replies; only message in thread
From: Chris Brenton @ 2003-12-22 12:37 UTC (permalink / raw)
To: netfilter
Greets all,
I figure Bill is too shy to point out all the excellent work he's done,
but I thought list members would find it interesting. ;-)
Check out Bill's firebrick project:
http://www.stearns.org/firebricks/
Firebrick is a set of independent modules that are designed to plug-in
to an iptables firewall. Some of the cooler modules:
* Filter legal but unallocated source IPs (common in spoof attacks)
* Identify probing based on inbound scan patters as well as outbound
unreachables
* Check/record/drop odd packet sizes (like non-terminal fragments
smaller than 512 bytes).
* Filter out all loose and strict source route packets
* When suspicious patterns are detected, drop and log all traffic from
that IP for 30 seconds
* Log SSH traffic using non-stand ports (other than 22/TCP)
* Record internal servers by monitoring outbound SYN/ACKs
There are others, but you get the idea. IMHO there are some extremely
useful tweaks up there that people can use.
HTH,
C
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2003-12-22 12:37 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-22 12:37 excellent rule archive Chris Brenton
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox