netfilter/iptables in kernel: module vs static
hey guys...
this seems to be the best place to ask this. im looking for advice on the subject [possibly several]. a little backgroud first. ive been trying to plug this hole: http://www.securityfocus.com/archive...9/2005-02-25/2 [over sized info querry causes immediate crash of any Quake3 based gaming engine] one method is to use the q3infofix_linux.c found here: http://aluigi.altervista.org/patches/q3infofix.zip so far, [sadly] the patch has not worked and i anticipate no fix forthcoming from ID software. so as the alternitive, ive been working on getting the hole plugged via iptables. here is the rule i have written, credit to SCDS_reyalP on the bani.anime.net forums for this. Quote:
Code:
Q3INFOBOOM_STRING="0>>22&0x3C@2&0xFFFF=0x2E4:0xFFFF && 0>>22&0x3C@8&0xFFFFFFFF=0xFFFFFFFF && 0>>22&0x3C@12&0xFFFFFFFF=0x67657469 && so, down to the questions. i currently have netfilter compiled into the kernel as static code, not modules. unfortunatley, i have not been able to call the u32 module. is this because i have the code compiled statically? [QoS is enabled - this was not my choice BTW, i prefer modules] from what i have been reading, not many people compile netfilter directly into the kernel. im hoping to do a recompile, but im just wondering _WHY_ i cant call the module properly. any info would be useful. |
AFAIK, the u32 match isn't normally part of the default iptables installation, so you need to patch the kernel with patch-o-matic (pom) in order to use the u32 match. Once patched you should see the u32 option appear in the kernel configuration menu ( during the make menuconfig or xconfig step), which you then need to enable before compiling. I'd also recommend including them as modules. For some reason people occasionally get odd results with them in the kernel.
|
u32 is acutally part of QoS.
yep. thats what im thinking too. ANY lib that i try and call is met with /lib/iptables/libipt_FOO not found. and the lib really is not there to call. this leads me to belive that there must be another way to call --match $SOME_FILTER with the code compiled statically, but i have yet to find this method. is netfilter-as-module the PREFERED method? |
Quote:
|
well... got u32 working properly. modules are loading, all is well.
still working on the actual SYNTAX of the cls_u32 rule. |
Could you post a brief writeup of the procedure you used? I haven't used the u32 match before, so I'm kind of curious of how you got it working (plus someone with a similar problem might find this thread via a search). Thanks.
|
All times are GMT -5. The time now is 04:16 PM. |