From 2dc8f4afde72f1fc1ea3f64135b36af9ee42e3e9 Mon Sep 17 00:00:00 2001 Message-Id: <2dc8f4afde72f1fc1ea3f64135b36af9ee42e3e9.1747427126.git.mdw@distorted.org.uk> From: Mark Wooding Date: Thu, 23 Jul 2009 12:24:08 +0100 Subject: [PATCH] vampire.m4: Log messages when rejecting DNS DDOS packets. Organization: Straylight/Edgeware From: Mark Wooding --- vampire.m4 | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/vampire.m4 b/vampire.m4 index 3a389ca..05a3293 100644 --- a/vampire.m4 +++ b/vampire.m4 @@ -36,10 +36,15 @@ m4_divert(-1) ###-------------------------------------------------------------------------- ### vampire-specific rules. +m4_divert(35)m4_dnl +errorchain ddos-evil-dns DROP +## Invalid DNS request with probably-forged sender address, with intent to +## cause DDOS. + m4_divert(82)m4_dnl ## Repelling evil DDos attack. run ipset -N ddos-evil-dns iphash 2>/dev/null || : -run iptables -A inbound -j DROP \ +run iptables -A inbound -g ddos-evil-dns \ -m set --set ddos-evil-dns src \ -p udp --destination-port $port_dns -- [mdw]