Comments: Some websites are maliciously attacked by UDP packet sending tools, leading to heavy traffic loss. Generally, only the DNS server uses udp protocol, while others can disable UDP packet forwarding, therefore, a script is written to allow only the UDP data packets of the target DNS server to go out. Some websites are maliciously attacked by UDP packet sending tools, leading to massive traffic loss.
Generally, only the DNS server uses the udp protocol, and other servers can disable UDP packet forwarding.
Therefore, a script is written to allow only UDP packets from the target DNS server to go out.
All other UDP packets are rejected.
This method can only prevent malicious UDP packets from being sent.
The server itself makes security settings to prevent malicious Trojans.
The Code is as follows:
#/Bin/bash
# Createdby http://www.jb51.net
# Drop udp Flood
List = 'grep nameserver/etc/resolv. conf | awk '{print $ NF }''
For I in $ list
Do
Iptables-a output-p udp-d $ I -- dport 53-j ACCEPT
Done
Iptables-a output-p udp-j DROP
Service iptables save