LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-14-2005, 10:38 PM   #1
sendas4
Member
 
Registered: May 2004
Location: Tacoma, Wa
Distribution: Gentoo
Posts: 94

Rep: Reputation: 15
How to block packets with certain terms


I am in need of help. There is this person I want to block from my network that uses a email address annoyinguy@email.com . His Msn also uses the same email.

My linux box is my networks firewall (gentoo iptables). Becuase email and msn isnt encrypted, Is it possible to block him by filtering all packets containing annoyingguy? Can I use iptables to do this?

- sen
 
Old 08-14-2005, 10:49 PM   #2
carl.waldbieser
Member
 
Registered: Jun 2005
Location: Pennsylvania
Distribution: Kubuntu
Posts: 197

Rep: Reputation: 32
Re: How to block packets with certain terms

Quote:
Originally posted by sendas4
I am in need of help. There is this person I want to block from my network that uses a email address annoyinguy@email.com . His Msn also uses the same email.

My linux box is my networks firewall (gentoo iptables). Becuase email and msn isnt encrypted, Is it possible to block him by filtering all packets containing annoyingguy? Can I use iptables to do this?

- sen
You can't do this with just pure iptables/netfilter, because iptables doesn't understand the protocols being used above the TCP layer (e.g. POP3, IMAP, HTTP, etc.). In order to do what you want to do, you need to use a filtering proxy. This link explains the difference: http://www.burningvoid.com/iaq/fwalltype.php
 
Old 08-14-2005, 10:55 PM   #3
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Even if you block those packets, it would make it impossible to download your email if it contains it in there. It would interrupt the TCP connection with your server (or the msn server) causing it to be reset.

Use protocol-based filtering.
 
Old 08-14-2005, 11:02 PM   #4
sendas4
Member
 
Registered: May 2004
Location: Tacoma, Wa
Distribution: Gentoo
Posts: 94

Original Poster
Rep: Reputation: 15
Thats a good point about it resetting. Wow that leaves me at a loss. Ive heard of packet injecting which seems similar to this idea. Would it be possible to filter his packet by just changing the contents of his message? so it would be a blank email or msn msg?

Last edited by sendas4; 08-14-2005 at 11:07 PM.
 
Old 08-15-2005, 12:09 AM   #5
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Well, then you have to take into account that an email can (and generally will) span more than one packet. And conversely, multiple emails can be in the same packet (when you receive over IMAP/POP, not SMTP). And of course, you'd need to adjust checksums and so forth.
 
Old 08-15-2005, 05:54 PM   #6
carl.waldbieser
Member
 
Registered: Jun 2005
Location: Pennsylvania
Distribution: Kubuntu
Posts: 197

Rep: Reputation: 32
Is it a POP3 account? Maybe you could use something like PopWash (http://www.dr-baum.net/popwash/ ) to find and delete his mails before downloading?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can we block arp packets? Linux.tar.gz Linux - Networking 13 09-13-2011 02:18 AM
Terms RodimusProblem General 6 01-20-2005 08:43 AM
encapsulating TCP packets in UDP packets... yoshi95 Programming 3 06-03-2004 02:53 PM
Linux Terms jesman_dell Linux - Newbie 8 01-08-2004 03:44 PM
Konsole vs other terms floyd Linux - Software 1 09-06-2003 10:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration