Honeypots mailing list archives

Re: Outgoing Traffic measure in OpenBSD an pf


From: "Earl Sammons" <esammons () hush com>
Date: Tue, 14 Dec 2004 09:28:56 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

How about "sessionlimit" from the Brazilian Honeynet team?

http://www.honeynet.org.br/tools/

Earl Sammons
esammons () hush com

On Mon, 13 Dec 2004 13:37:00 -0800 =?ISO-8859-
1?Q?David_Jim=E9nez_Dom=EDnguez?= <djdsecurity () gmail com> wrote:
Hi list!!

I had an OpenBSD as my firewall and I would like tu measure the
Outgoing traffic in order to detect activity in my HoneyNet and
add a
pf rule to block the activity in the HoneyPot (just like HoneyWall
works...but in OpenBSD).....

I haven't found a way to do that, is there a parameter in pf like -

m
limit in iptables??

Sia
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4

wkYEARECAAYFAkG/IuIACgkQk7+e+4lPSm11yACeLuEDry0NIMjdIaYU4/jLJGAdb5gA
n04YiZc+wUNLw+LkLKuNsgVlpxzt
=iCwH
-----END PGP SIGNATURE-----




Concerned about your privacy? Follow this link to get
secure FREE email: http://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
http://www.hushmail.com/services-messenger?l=434

Promote security and make money with the Hushmail Affiliate Program: 
http://www.hushmail.com/about-affiliate?l=427


Current thread: