Client Authentication

Michael Ross gmx at ross.cx
Wed Mar 27 01:59:17 UTC 2013


On Wed, 27 Mar 2013 01:37:36 +0100, Daniel O'Callaghan  
<danny at clari.net.au> wrote:

> On 27/03/2013 10:37 AM, Michael Ross wrote:
>>> I'm happy to share a program I wrote which slows down the brute force  
>>> attackers.
>>> It simply counts the SYN packets from a given IP and limits the rate  
>>> per minute by dropping the packet if they are coming too fast.
>>>
>>> Uses ipfw divert sockets, so would work if you prefer ipfw over pf.
>>
>> Me Me Me! ...ahem.
>> I do prefer IPFW over PF and would very much like to try it out,
>> so please do share.
> OK, here 'tis
>
> https://secure.clari.net.au/ratelimit2.tgz
>
> Danny

Thanks!

I'd like to be able to change the time window:

http://gurder.ross.cx/misc/ratelimit.patch



Regards,

Michael


More information about the freebsd-questions mailing list