Initial commit.

Populate the iptables-addons repository with two modules, xt_TARPIT
and xt_TEE, as a starting point.

Signed-off-by: Jan Engelhardt <jengelh@computergmbh.de>
This commit is contained in:
Jan Engelhardt
2008-01-29 03:57:08 +01:00
commit 7a981b17b5
16 changed files with 894 additions and 0 deletions

View File

@@ -0,0 +1,16 @@
config NETFILTER_XT_TARGET_TARPIT
tristate '"TARPIT" target support'
depends on NETFILTER_XTABLES
---help---
Adds a TARPIT target to iptables, which captures and holds incoming TCP
connections using no local per-connection resources. Connections are
accepted, but immediately switched to the persist state (0 byte
window), in which the remote side stops sending data and asks to
continue every 60-240 seconds. Attempts to close the connection are
ignored, forcing the remote side to time out the connection in 12-24
minutes.
This offers similar functionality to LaBrea
<http://www.hackbusters.net/LaBrea/>, but does not require dedicated
hardware or IPs. Any TCP port that you would normally DROP or REJECT
can instead become a tar pit.