add example icmp drop script
This commit is contained in:
2
backend/example_scripts/icmp-drop-requirements.txt
Normal file
2
backend/example_scripts/icmp-drop-requirements.txt
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
netfilterqueue
|
||||||
|
scapy
|
||||||
38
backend/example_scripts/icmp_drop.py
Normal file
38
backend/example_scripts/icmp_drop.py
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
|
||||||
|
#!/usr/bin/env python3
|
||||||
|
# drop_icmp_v4.py
|
||||||
|
# Requirements: NetfilterQueue, scapy
|
||||||
|
|
||||||
|
import sys
|
||||||
|
from netfilterqueue import NetfilterQueue
|
||||||
|
from scapy.all import IP
|
||||||
|
|
||||||
|
def on_packet(pkt):
|
||||||
|
data = pkt.get_payload()
|
||||||
|
try:
|
||||||
|
ip = IP(data)
|
||||||
|
# IPv4 ICMP protocol number == 1
|
||||||
|
if ip.proto == 1:
|
||||||
|
pkt.drop()
|
||||||
|
return
|
||||||
|
except Exception:
|
||||||
|
# parsing error -> accept (conservative choice)
|
||||||
|
pass
|
||||||
|
pkt.accept()
|
||||||
|
|
||||||
|
def main():
|
||||||
|
if len(sys.argv) < 2:
|
||||||
|
print("Usage: drop_icmp_v4.py <QUEUE_NUM>", file=sys.stderr)
|
||||||
|
sys.exit(1)
|
||||||
|
qnum = int(sys.argv[1])
|
||||||
|
nfq = NetfilterQueue()
|
||||||
|
nfq.bind(qnum, on_packet)
|
||||||
|
try:
|
||||||
|
nfq.run()
|
||||||
|
except KeyboardInterrupt:
|
||||||
|
pass
|
||||||
|
finally:
|
||||||
|
nfq.unbind()
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
Reference in New Issue
Block a user