Interrupting worms How To?
In our company we use linux gateway (iptables based).But now adays we got lots of ICMP traffic, how can i stop this.Our link is to slow.With Iptables rules worms can be stopped?? Or Doyou advice something different??
|
Iptables Rules
|
I do it thru /proc/sys, look in /proc/sys/net/ipv4
echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all But don't quote me on this one.... |
Worm will try to propagate by scanning network ranges. If you have no dealings with these ranges, and if you have vulnerable systems add blocking rules. Adding an IDS like Snort should prove beneficial too.
|
All times are GMT -5. The time now is 10:58 PM. |