From 2ab1141b888a06b6523f452c1613c84357e3c6c9 Mon Sep 17 00:00:00 2001 From: bol-van Date: Sat, 2 Mar 2024 17:59:08 +0300 Subject: [PATCH] readme.eng.md : minor fix --- docs/readme.eng.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/readme.eng.md b/docs/readme.eng.md index 5d4d5c0..ba0b97e 100644 --- a/docs/readme.eng.md +++ b/docs/readme.eng.md @@ -99,7 +99,7 @@ Its necessary to use this filter when also using `connbytes 1:6`. Without it pac Some attacks require redirection of incoming packets : -iptables -t mangle -I PREROUTING -i -p tcp --sport 80 -m connbytes --connbytes-dir=reply --connbytes-mode=packets --connbytes 1:6 -m set --match-set zapret src -j NFQUEUE --queue-num 200 --queue-bypass +`iptables -t mangle -I PREROUTING -i -p tcp --sport 80 -m connbytes --connbytes-dir=reply --connbytes-mode=packets --connbytes 1:6 -m set --match-set zapret src -j NFQUEUE --queue-num 200 --queue-bypass` Incoming packets are filtered by incoming interface, source port and IP. This is opposite to the direct rule.