Files
xtables-addons/extensions/pknock
Jan Rafaj 08f6a82bdc pknock: avoid fillup of peer table during DDoS
In TCP --strict mode, forget the peer which sent the wrong knock in a
sequence, rather than resetting its status to ST_INIT. This avoids
filling up the peer table (which would lead to pknock DoS) in case of
a DDoS attack performed by a set of port-scanning malicious hosts.
2009-10-11 01:48:20 +02:00
..
2009-10-09 17:50:05 +02:00
2009-10-09 17:50:05 +02:00
2009-10-09 18:11:49 +02:00