If you are going to undertake the noble task of sucking up their bandwidth, then I'd suggest that you do the job thoroughly, and make sure that their TCP stack decides to retransmit as many packets as possible. Use iptables (for instance) to selectively/randomly drop packets.

That's brilliant! does iptables have a TARPIT target that causes the peer to retransmit as much as possible? Can we add one?

There are quite a few cool patches to netfilter that might be useful:


http://www.netfilter.org/documentation/HOWTO//netfilter-extensions-HOWTO-3.html

With regards to tarpitting, we could do a few things. The "random" patch would be good for keeping craphosts busy. With "iplimit", we could limit the amount of incoming connections allowed at a time by the remote MTA wannabe to 1 or 2. And, with the "fuzzy" or "quota" patches you could cause all kinds of havoc. :)

Hmmm.. makes me want to go and play. :)

-- Bryan



Reply via email to