LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-22-2007, 06:34 PM   #1
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Rep: Reputation: 15
2p2 killing me again


hello friends,

i have successfully blocked a good number of peer 2 peer protocols such as gnutella, fasttrack,edonkey using an iptables modules called rope. but the problem now is i suddenly discovered this new p2p called ARES. i really want to block this thing from consuming my entire bandwidth. but unfortunately rope does not have a script for this ARES. can any one assist on what step to take.

Thanks in Advance.
 
Old 06-22-2007, 07:09 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Maybe look into the IPP2P project. Their website lists Ares as one of the P2P networks which their iptables module can match.

Last edited by win32sux; 06-22-2007 at 07:25 PM.
 
Old 06-23-2007, 03:16 AM   #3
sakimustafa
LQ Newbie
 
Registered: Jun 2007
Posts: 2

Rep: Reputation: 0
Try with l7 netfilter patch
 
Old 06-23-2007, 10:13 AM   #4
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Original Poster
Rep: Reputation: 15
Thanks guys for the quick response, ipp2p does a very good work but still not blocking this particular variant of Ares called Ares regular. pls let me know if there is another option.

Thnaks
 
Old 06-24-2007, 06:45 AM   #5
v00d00101
Member
 
Registered: Jun 2003
Location: UK
Distribution: Devuan Beowulf
Posts: 514
Blog Entries: 1

Rep: Reputation: 37
Close all ports and force web traffic via a proxy like squid.

As i remember even Ares needs a port open to function properly. If you lock down all ports, then force everything through squid, you can tailor exactly what gets access, and also weight things, so perceived p2p traffic gets a hellishly low priority, while http(s) gets a higher priority, etc.

Guides on how to do this exist and can be found via the usual routes (google, etc).

Also maybe look into dansguardian and moblock.
 
Old 06-24-2007, 10:18 AM   #6
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Original Poster
Rep: Reputation: 15
thanks v00d00101,

could u give me a hint on how i could use squid to attain this after blocking all ports.

Thnaks
 
Old 06-24-2007, 05:18 PM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by yawe_frek
ipp2p does a very good work but still not blocking this particular variant of Ares called Ares regular.
Does it say that on the website or did you try it yourself? BTW, if the ipp2p people have a mailing list it might be a good idea to ask about this there.

Quote:
Originally Posted by yawe_frek
could u give me a hint on how i could use squid to attain this after blocking all ports.
What you will be able do with Squid is gonna be very limited IMHO (unless Ares has no proxy compatibility at all). If you wish to go the proxy route, I'd say your best bet would be an application-layer proxy. A lot of people like Zorp.

Last edited by win32sux; 06-24-2007 at 05:21 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
This is killing me UncleEricB Linux - Networking 2 02-01-2005 09:41 PM
Kernel keeps killing X Kyanos Linux - Software 2 10-24-2004 10:28 PM
2.6.3 is killing me, many errors help!! dhbiker Slackware 11 03-06-2004 11:13 PM
killing X jabberwock486 Linux - Newbie 7 09-10-2003 11:59 AM
Killing X ? sp0t Linux - Newbie 7 08-17-2002 07:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration