par lucyfire » 15 Mai 2003 10:03
ça marche au poil évidement ! j'y ai pas pensé du tout j'aurais trouvé pour rc.sysinit mais pas pour la reconnecion en rc.updatered
<BR>
<BR>merci.
<BR>
<BR>voilà le script entier qui permet de se debarraser de msn mess yahoo mess et aol mess la section kazaa n'est pas encore testé. Je n'ai rien contre ces programmes mais dans un lycée ça evite de daubé mes stations.
<BR>
<BR>#!/bin/sh
<BR>
<BR>/sbin/iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -j MASQUERADE
<BR>
<BR># Msn Messenger
<BR>/sbin/iptables -I FORWARD -s 192.168.2.0/24 -p tcp --dport 1863 -j DROP
<BR>
<BR># AOL Messenger
<BR>/sbin/iptables -I FORWARD -s 192.168.2.0/24 -p tcp --dport 5190 -j DROP
<BR>/sbin/iptables -I FORWARD -s 192.168.2.0/24 -p tcp --dport 4099 -j DROP
<BR>
<BR># Yahoo Messenger
<BR>
<BR>/sbin/iptables -I FORWARD -s 192.168.2.0/24 -p tcp --dport 5050 -j DROP
<BR>/sbin/iptables -I FORWARD -d scs.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scsa.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d cs.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-fooa.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-foob.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-fooc.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-food.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-fooe.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d scs-foof.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d http.pager.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d msg.edit.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d chat.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d messenger.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>/sbin/iptables -I FORWARD -d address.yahoo.com -m state --state NEW,RELATED,ESTABLISHED -j DROP
<BR>
<BR># Kazaa
<BR>#/sbin/iptables -A INPUT -i ppp0 -p tcp --dport 1214 -j REJECT --reject-with tcp-reset
<BR>#/sbin/iptables -A FORWARD -i ppp0 -p tcp --dport 1214 -j REJECT --reject-with tcp-reset
<BR>#/sbin/iptables -I FORWARD -p tcp -m string --string "KazaaClient" -j REJECT --reject-with tcp-reset
<BR>
"Les hommes déprécient ce qu'ils ne peuvent comprendre." [Goethe]