can pf block a string ? or better, to limit it ?

claudiu vasadi claudiu.vasadi at gmail.com
Wed Jun 23 18:58:31 UTC 2010


Hello fellas,


system: freebsd 8.0 with pf


A couple of years ago I wanted to limit a string with pf and I could not
find a way to do it.

Back in the day, I was running a dc++ software on FreeBSD and the most
common way of flood was this "string attack". The idea was simple: more than
"x" number of packages containing this "string" = dc++ software stuck. I
remember a friend of mine was able to limit the number per second to
something but I was unable to do the same in pf. Back then I was using
FreeBSD6.2 but I can't find a way to do it even now.


Can someone shed some light ? Were you trying something similar ?


More information about the freebsd-pf mailing list