From owner-freebsd-net@FreeBSD.ORG Fri Jan 16 11:09:46 2009 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DFC4B10656F4 for ; Fri, 16 Jan 2009 11:09:46 +0000 (UTC) (envelope-from dimitar.vassilev@gmail.com) Received: from mail-gx0-f21.google.com (mail-gx0-f21.google.com [209.85.217.21]) by mx1.freebsd.org (Postfix) with ESMTP id 833818FC16 for ; Fri, 16 Jan 2009 11:09:46 +0000 (UTC) (envelope-from dimitar.vassilev@gmail.com) Received: by gxk14 with SMTP id 14so1709256gxk.19 for ; Fri, 16 Jan 2009 03:09:45 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type; bh=1M0pvJ4L8ef2nSBRRUwbKu1CQiEJrluMn83uWDUMS8Y=; b=kT34jy2yuFNcmOLDtlEbwgkR0EDs0g4U5MSPVFjjKaSseyaGWQmbSRcAlKwrmJEQzY pyTODdzO9IBC/efw0J5Ca1rVc8lkB1QNwMFQunOwzIwx7ptGUnGzdzcFL7icRw1zNkjZ 3+etjlbK8qKFgCa4Tlf2545VjjsRXPJAMWVMg= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=uPj8pc8fn7lpS+/Jy7uX8Wz5F2qBS4Ra2ZtGkMLOipbw+lnkanB2pnskt5nMFpWSU/ Jdyb2Bk8z/q62LafgsT8blbfixEqqCYJtLMi/XEIHYHZGKEHtau9qogkhBz831uG+yCw pPMM/36v6iMhWtxAqu9j0wg7+gV6j5cWNgttA= MIME-Version: 1.0 Received: by 10.150.156.9 with SMTP id d9mr5872905ybe.187.1232103206264; Fri, 16 Jan 2009 02:53:26 -0800 (PST) In-Reply-To: References: Date: Fri, 16 Jan 2009 12:52:56 +0200 Message-ID: <59adc1a0901160252w2f4c47bbs66db4ab377024784@mail.gmail.com> From: Dimitar Vasilev To: Vlad GALU Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-net@freebsd.org, Ivo Vachkov , Alexey Ivanov Subject: Re: TARPIT for pf/ipfw X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 16 Jan 2009 11:09:47 -0000 see spamd for mail and you may use the don't peer list of sbl . 2009/1/16 Vlad GALU > This particular iptables module keeps the incoming connection up and > running, but it sends ACKs advertising a window size of 0 bytes, so > that the remote end can't send any data until the local process has > decided it's ok to do so. Basically it's used to slow down spammers > and worms. > > On Fri, Jan 16, 2009 at 11:31 AM, Ivo Vachkov > wrote: > > what does TARPIT do ? > > > > On Fri, Jan 16, 2009 at 11:20 AM, Alexey Ivanov wrote: > >> Is there any command identical to: > >> iptables -A INPUT -p tcp -m tcp -dport 80 -j TARPIT > >> > >> If no, does anyone ever tried to implement this feature? > >> > >> _______________________________________________ > >> freebsd-net@freebsd.org mailing list > >> http://lists.freebsd.org/mailman/listinfo/freebsd-net > >> To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" > >> > > > > > > > > -- > > "UNIX is basically a simple operating system, but you have to be a > > genius to understand the simplicity." Dennis Ritchie > > _______________________________________________ > > freebsd-net@freebsd.org mailing list > > http://lists.freebsd.org/mailman/listinfo/freebsd-net > > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" > > > > > > -- > ~/.signature: no such file or directory > _______________________________________________ > freebsd-net@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-net > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" >