Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Newer
Older
100644 25 lines (23 sloc) 1.161 kB
187ea2f @mrash Added psad_auto_ips into cvs
authored
1 #
e7077a0 @mrash comment fixes
authored
2 #############################################################################
3 #
17a5fd6 @mrash implemented the ability to assign danger levels based on tcp/udp port…
authored
4 # This file is used by psad to elevate/decrease the danger levels of IP
e7077a0 @mrash comment fixes
authored
5 # addresses (or networks in CIDR notation) so that psad does not have to
17a5fd6 @mrash implemented the ability to assign danger levels based on tcp/udp port…
authored
6 # apply the normal signature logic. This is useful if certain IP addresses
e7077a0 @mrash comment fixes
authored
7 # or networks are known trouble makers and should automatically be assigned
8 # higher danger levels than would normally be assigned. Also, psad can be
17a5fd6 @mrash implemented the ability to assign danger levels based on tcp/udp port…
authored
9 # made to ignore certain IP addresses or networks if a danger level of "0" is
6f3f1a5 @mrash updated comments to indicate new protocol-specific danger levels
authored
10 # specified. Optionally, danger levels for IPs/networks can be influenced
11 # based on protocol (tcp, udp, icmp).
d553ba2 @mrash minor text formatting changes
authored
12 #
e7077a0 @mrash comment fixes
authored
13 #############################################################################
14 #
d553ba2 @mrash minor text formatting changes
authored
15
17a5fd6 @mrash implemented the ability to assign danger levels based on tcp/udp port…
authored
16 # <IP address> <danger level> <optional protocol>/<optional ports>;
d553ba2 @mrash minor text formatting changes
authored
17 #
e7077a0 @mrash comment fixes
authored
18 # Examples:
187ea2f @mrash Added psad_auto_ips into cvs
authored
19 #
cb891a8 @mrash minor auto_dl spacing update
authored
20 # 10.111.21.23 5; # Very bad IP.
21 # 127.0.0.1 0; # Ignore this IP.
22 # 10.10.1.0/24 0; # Ignore traffic from this entire class C.
23 # 192.168.10.4 3 tcp; # Assign danger level 3 if protocol is tcp.
24 # 10.10.1.0/24 3 tcp/1-1024; # Danger level 3 for tcp port range
Something went wrong with that request. Please try again.