ipset create scanner-ip-set hash:ip
iptables \
-A INPUT \
-p tcp --syn ! --dport 12345 \
-j SET --add-set scanner-ip-set src
watch -n1 \
ipset list scanner-ip-set
iptables \
-A INPUT \
-p tcp --syn ! --dport 12345 \
-j DROP
iptables \
-A INPUT \
-p tcp --syn \
-m set --match-set scanner-ip-set src \
-j DROP
ipset create scanner-ip-set hash:ip timeout 30
ipset create scanner-ip-set hash:ip timeout 30 counters
iptables \
-A INPUT \
-p tcp --syn \
-m set --match-set scanner-ip-set src \
--packets-gt 5 \
-j DROP
iptables \
-A INPUT \
-p tcp ! --syn \
-m conntrack ! --ctstate ESTABLISHED \
-j DROP
ipset create pub-port-set bitmap:port range 0-65535
iptables \
-A INPUT \
-p tcp --syn \
-m set ! --match-set pub-port-set dst \
-j SET --add-set scanner-ip-set src
ipset add pub-port-set 12345
欢迎光临 黑帽联盟 (https://bbs.cnblackhat.com/) | Powered by Discuz! X2.5 |