Floodmon is a small Perl daemon used to monitor a Linux server for SYN flood attacks (Dos DDos), to alert the administrator and to mitigate the attack in order to allow legitimate connections to succeed (HTTP, POP3, SMTP...).
Very useful tool. I'm surprised I haven't heard about it before... It really does work, and helped mitigate a synflood against httpd.
v0.9.3 (25-June-2009) [+] added '--capture' option for on-demand capture of SYN packets. Capture can be saved to disk or sent by email. [-] fixed NETMASK bug. [+] munin-node stats modification : they now display the current amount of half-opened connections (SYN_RECV) per level. [+] added new iptables rules (invalid flags). [+] either nf_* or ipt_* keys will be used for the connection tracking table.
v0.9.3 (25-June-2009) [+] added '--capture' option for on-demand capture of SYN packets. Capture can be saved to disk or sent by email. [-] fixed NETMASK bug. [+] munin-node stats modification : they now display the current amount of half-opened connections (SYN_RECV) per level. [+] added new iptables rules (invalid flags). [+] either nf_* or ipt_* keys will be used for the connection tracking table.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: