Useful addition to ipfw

看板FB_security作者時間20年前 (2005/12/14 00:10), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Hello, I've found myself in a situation where a simple data inspection capability added to ipfw would be very useful. I'm not thinking about anything especially sophisticated, but what about adding an option to check byte values (or flags, similar to tcpdump)? An example rule could be: add deny udp from any to me 12345 udp[4]&234 being the rule true if byte 4 in the UDP packet AND the number 234 is not zero. P.S: I'm thinking about controlling some types of UDP packets than can be identified by simple flags present in the packet data. Opinions? Borja. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #13dl9P00 (FB_security)
文章代碼(AID): #13dl9P00 (FB_security)