denyhosts-like app for MySQLd?

Tim Priebe tim at priebe.alt.na
Mon Jan 21 02:52:12 PST 2008


On Monday 21 January 2008 12:35:51 pm Jordi Espasa Clofent wrote:
> > Hi,
> >
> > There is a functionality in pf, that allows you to have an application to
> > update a list of hosts, that is used in a rule. You could have a script
> > harvest the addresses from your log files, and then update the table in
> > pf. I have not tried it myself, but was looking at adopting an
> > implementation to create a tarpit for spammers based on this idea.
>
> Yes Tim, I know it. The "problem" is the servers are builded in IPFW as
> firewall solution.
> I've tried the "limit" IPFW's option... but isn't exactly what I'm
> looking for.

As far as I know you can run both. You can just have minimal rules in pf to 
deal with this, and pass everything else, and deal with the rest in ipfw.


More information about the freebsd-security mailing list