From owner-freebsd-pf@FreeBSD.ORG Tue May 16 05:04:08 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 37BBF16A4EF for ; Tue, 16 May 2006 05:04:08 +0000 (UTC) (envelope-from solinym@gmail.com) Received: from ug-out-1314.google.com (ug-out-1314.google.com [66.249.92.172]) by mx1.FreeBSD.org (Postfix) with ESMTP id 884E843D46 for ; Tue, 16 May 2006 05:04:07 +0000 (GMT) (envelope-from solinym@gmail.com) Received: by ug-out-1314.google.com with SMTP id m2so647278uge for ; Mon, 15 May 2006 22:04:04 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=RKS5vVikinN7ZxDHiymXimg8UJgAAF3jff6AeaNOm7Izv7CwzZN/FHuVCG8aaPfAfBXmE1iP7oNbFK+aRFWttQhqJ0kcdUcCr/TxiJi9N8vBhFMT1OgGAJHPWi4CAJfEsjwaETTX3tEZuig0BahVE7QXfWMC75Cjr7aDV/63dh4= Received: by 10.78.67.20 with SMTP id p20mr1361628hua; Mon, 15 May 2006 22:04:04 -0700 (PDT) Received: by 10.78.58.20 with HTTP; Mon, 15 May 2006 22:04:04 -0700 (PDT) Message-ID: Date: Tue, 16 May 2006 00:04:04 -0500 From: "Travis H." To: "Lyndon Nerenberg" In-Reply-To: <340DFC1B-2620-4997-B495-67FA88F8662F@orthanc.ca> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <44680266.2090007@azimut-tour.ru> <446873D3.7090703@azimut-tour.ru> <55e8a96c0605150907k49af4454t5d0431ea036e11bc@mail.gmail.com> <200605151823.17265.viktor.vasilev@stud.tu-darmstadt.de> <55278.192.168.4.1.1147735542.squirrel@mail.abi01.homeunix.org> <340DFC1B-2620-4997-B495-67FA88F8662F@orthanc.ca> Cc: freebsd-pf@freebsd.org Subject: Re: promt solution with max-src-conn-rate X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 May 2006 05:04:53 -0000 I also have plans to write a sniffer to detect this kind of misuse without log-parsing, and the idea is to implement it at your gateway choke-point so it can detect it against any inbound connection, regardless of the ultimate source. Sorry to mention vaporware, but I'm pretty close to finishing it -- I have a sniffer that detects bittorrent traffic behind NAT and sets up rdr rules to support it. It's also a logical step to do port knocking (a/k/a single packet authentication) by sniffing the pflog interface and capturing the full content of blocked packets. I intend to do that as well. --=20 "Curiousity killed the cat, but for a while I was a suspect" -- Steven Wrig= ht Security Guru for Hire http://www.lightconsulting.com/~travis/ -><- GPG fingerprint: 9D3F 395A DAC5 5CCC 9066 151D 0A6B 4098 0C55 1484