From d90c5e165021e8a9138e5bc965f9c9e6bd47d238 Mon Sep 17 00:00:00 2001 From: malmert Date: Fri, 17 Apr 2026 21:36:00 +0200 Subject: [PATCH] add example icmp drop script --- .../icmp-drop-requirements.txt | 2 + backend/example_scripts/icmp_drop.py | 38 +++++++++++++++++++ 2 files changed, 40 insertions(+) create mode 100644 backend/example_scripts/icmp-drop-requirements.txt create mode 100644 backend/example_scripts/icmp_drop.py diff --git a/backend/example_scripts/icmp-drop-requirements.txt b/backend/example_scripts/icmp-drop-requirements.txt new file mode 100644 index 0000000..74cc766 --- /dev/null +++ b/backend/example_scripts/icmp-drop-requirements.txt @@ -0,0 +1,2 @@ + netfilterqueue +scapy diff --git a/backend/example_scripts/icmp_drop.py b/backend/example_scripts/icmp_drop.py new file mode 100644 index 0000000..91c2915 --- /dev/null +++ b/backend/example_scripts/icmp_drop.py @@ -0,0 +1,38 @@ + +#!/usr/bin/env python3 +# drop_icmp_v4.py +# Requirements: NetfilterQueue, scapy + +import sys +from netfilterqueue import NetfilterQueue +from scapy.all import IP + +def on_packet(pkt): + data = pkt.get_payload() + try: + ip = IP(data) + # IPv4 ICMP protocol number == 1 + if ip.proto == 1: + pkt.drop() + return + except Exception: + # parsing error -> accept (conservative choice) + pass + pkt.accept() + +def main(): + if len(sys.argv) < 2: + print("Usage: drop_icmp_v4.py ", file=sys.stderr) + sys.exit(1) + qnum = int(sys.argv[1]) + nfq = NetfilterQueue() + nfq.bind(qnum, on_packet) + try: + nfq.run() + except KeyboardInterrupt: + pass + finally: + nfq.unbind() + +if __name__ == "__main__": + main()