From 2e6ddc4756ab5decaba59932d531a0f056d12d26 Mon Sep 17 00:00:00 2001 From: bol-van Date: Fri, 19 Apr 2024 09:08:12 +0300 Subject: [PATCH] docs iptables: remove unneeded --- docs/iptables.txt | 5 ----- 1 file changed, 5 deletions(-) diff --git a/docs/iptables.txt b/docs/iptables.txt index 2b396ac..4e319e0 100644 --- a/docs/iptables.txt +++ b/docs/iptables.txt @@ -3,11 +3,6 @@ For window size changing : iptables -t mangle -I PREROUTING -p tcp --sport 80 --tcp-flags SYN,ACK SYN,ACK -j NFQUEUE --queue-num 200 --queue-bypass iptables -t mangle -I PREROUTING -p tcp --sport 80 --tcp-flags SYN,ACK SYN,ACK -m set --match-set zapret src -j NFQUEUE --queue-num 200 --queue-bypass -For outgoing data manipulation ("Host:" case changing) : - -iptables -t mangle -I POSTROUTING -p tcp --dport 80 -m set --match-set zapret dst -j NFQUEUE --queue-num 200 --queue-bypass -iptables -t mangle -I POSTROUTING -p tcp --dport 80 -m set --match-set zapret dst -m connbytes --connbytes-dir=original --connbytes-mode=packets --connbytes 1:6 -j NFQUEUE --queue-num 200 --queue-bypass - For dpi desync attack : iptables -t mangle -I POSTROUTING -p tcp -m multiport --dports 80,443 -m connbytes --connbytes-dir=original --connbytes-mode=packets --connbytes 1:6 -m mark ! --mark 0x40000000/0x40000000 -j NFQUEUE --queue-num 200 --queue-bypass