4 ms·
Maybe tarpit[1] the connections? By rejecting them quickly you help them move on, but if you instead make the pages load as slowly as possible that would waste
by discreditable 8y ago
Maybe tarpit[1] the connections? By rejecting them quickly you help them move on, but if you instead make the pages load as slowly as possible that would waste a lot of their time.
1. https://en.wikipedia.org/wiki/Tarpit_(networking) https://en.wikipedia.org/wiki/Tarpit_(networking)
- jquinby 8y agoI thought this same thing. Figuring out who/when to tarpit might be a little tricky, but here's the basic approach for a Debian system via iptables: https://sysadminblog.net/2013/08/debian-iptables-tarpit/ https://sysadminblog.net/2013/08/debian-iptables-tarpit/
- Cieplak 8y agoCame here to suggest that, too. Here’s a tutorial on doing it with the pf firewall: https://home.nuug.no/~peter/pf/en/bruteforce.html https://home.nuug.no/~peter/pf/en/bruteforce.html