|
From: Friedrich L. <fl...@fl...> - 2003-05-29 20:03:02
|
Bruce Smith wrote: > > Correct if I'm wrong, but since it's jumping to LOG, it's not preventing > anything (LOG returns after logging the packet). So it's only logging > the over-limits, and not doing anything to stop DOS attacks. The limit stops someone from doing a DOS attack on your syslog server. If you do $IPTABLES -A FORWARD -j LOG --log-prefix "FORWARD: " Then every user can bring your machine to its knees by sending a lot of packets. You get the idea? > I guess it's relying on the catch-all policy of DENY to stop anything > that's not accepted (including DOS attacks). DOS needs a service that can be abused so it eventually dieds and so does the whole machine. > So it really does no good in my script, other than maybe saving a few > entries in the log. Is that really needed? Syslog normally combines > duplicate entries anyway. See above. Syslog will log _each_ packet, as each packet usually has a uniq or at least different id tag. I actually would need two different packets to doe the DOS - both having a different id tag (or sequence number in TCP) and sending them alternating. Now way syslog can combine those log entries. > I have seen specific "--limit" iptable statements specific for different > kind of DOS attacks, but I don't remember where I saw them off hand. > And now I'm not sure they are needed ... Anyone? Of course you can use limit not just with logging. But what you'll have for now will do. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |