Mensaje archivado #869 de la Lista ecs-isp@2rosenthals.com | volver a la lista |
|
---|
In <list-3273592@2rosenthals.com>, on 11/20/19
at 11:01 PM, "Massimo S." <ecs-isp@2rosenthals.com> said:
Hi Massimo,
anyone knows if there is a way to write an injoy fw rules that close a
number of connections in "SYN_RCVED" state?
0 STREAM 36488 http..80 136.243.53.94 SYN_RCVED
0 STREAM 21095 http..80 136.243.53.94 SYN_RCVED
0 STREAM 11324 http..80 136.243.53.94 SYN_RCVED
0 STREAM 52846 http..80 136.243.53.94 SYN_RCVED
0 STREAM 63960 http..80 136.243.53.94 SYN_RCVED
Take a look at the SYN-Flood rule in
rulelib\dos\flood.cnf
i've seen there stuff something like this:
Flags = "+ACK",
but it's not documented, afaik...
It is, but not in tutorial form.
firerule.dct defines:
ATTRIBUTE Flags 68 string
Unfortunately, Flags is a string so you have to search the .cnf files in
the rulelib directory tree for valid values, but there are a number of
examples.
Steven
Suscribirse: Todos,
Compendio,
Indice. Desuscribirse Correo al dueño de la Lista |