|
楼主 |
发表于 2008-5-2 23:22:47
|
显示全部楼层
LnS 所有 Plugin 和 一些知識
LnS 所有 Plugin 和 一些知识
LnS 所有 Plugin 和 一些知识
UDP规则位置 :
UDP 规则可放在 ‘+Anti-IP Spoofing’ 或 ‘+ACK-URG’ 之下 , 两者也没有分别 .
TCP规则位置 :
如果是服务器规则 ( server rule ) , 应该放在 +TCP:Block Incoming Connections 之上
如果是服务器规则 ( client rule ) , 应该放在 +TCP:Block Incoming Connections 之下
P.S. 是以 Phant0m rule set 作准则
====================================================
Multi-Port Banlist (24.5 KB)
Description: This little different, you can create rules containing up-to 7 specified ports, any TCP or UDP inbound packets with source-ports specified will trigger the rule.
描述: 这一点不同, 您能创造规则包含7个 指定的 TCP 或 UDP 端口 , 任何一个 TCP 或 UDP 入站小包与来源端口被指定将触发规则。
Multi-MAC Banlist (27.5 KB)
Updated last: Monday, January 15, 2007 (v1.01)
Description: Permits a single rule on the Internet filtering screen to block multiple MAC addresses up-to 10 entries.
描述: 允许一个唯一规则在互联网过滤的屏幕阻拦多个MAC 地址 ( 最多10个 )。
Multi-IP Banlist (24.0 KB)
Updated last: Sunday, January 14, 2007 (v1.01)
Description: Permits a single rule on the Internet filtering screen to block multiple IP addresses up-to 10 entries
描述: 允许一个唯一规则在互联网过滤的屏幕阻拦多个IP 地址 ( 最多10个 )
Ruleset Validator (8.0 KB) {本人没用过}
Description: Ensures your current Ruleset hasn’t been emptied or maliciously t[wiki]amp[/wiki]ered, the checks are always performed as Look ‘n’ Stop loads
描述: 保证您当前的Ruleset 未被倒空或恶意地窜改, 当LnS装载时便会执行检查
====================================================
有关 PluginEditRawRule.dll
What is it? And what does it offer me?
This is a Plug-In for Look ‘n’ Stop; it adds extended capabilities for rules creations, you can filter at a raw-level (lowest level possible), filter by anything in the entire packet header...
These are the basics what we must know;
---
A raw rule is defined by:
- The rule name
- The rule description
- The packet direction to which the rule applies: inbound, outbound or both
- 1 to 10 fields
An Ethernet packet that goes through the Internet filtering matches a rule if all fields of the rule match the corresponding packet fields.
A field is defined by:
- The field identifier: 0 to 9
- The field size: 1 to 6 bytes
- The field offset type: Ethernet, IP, TCP
- The field offset for inbound packets (relative to offset type)
- The field offset for outbound packets (relative to offset type)
- The field criteria
- The field Value1, Value2 and Mask.
About the field offset type:
If the offset type is Ethernet, the field offset (inbound or outbound) starts "0 bytes" after the Ethernet packet first byte.
If the offset type is IP, the field offset (inbound or outbound) starts "18 bytes" after the Ethernet packet first byte.
If the offset type is TCP, the field offset (inbound or outbound) starts "34+4+IHL bytes" after the Ethernet packet first byte. (IHL = IP Header Length).
The field criteria may be one of these:
- NA: Not Applicable field (default)
- EQUAL_VALUE1: Field equals to Value1
- NOTEQUAL_VALUE1: Field not equal to Value1
- RANGE_IN: Field is in the Value1:Value2 range
- RANGE_OUT: Field is out the Value1:Value2 range
- MASK_VALUE1: (Field and Mask) equal to Value1
- NOTMASK_VALUE1: (Field and Mask) not equal to Value1
- RANGE_IN_REV: Field is in the Value1:Value2 range (reverse byte order)
- RANGE_OUT_REV: Field is out of the Value1:Value2 range (reverse byte order)
- EQUAL_VALUE1OR2: Field equals to Value1 or Value2
- NOTEQUAL_VALUE1AND2: Field different from both Value1 and Value2
- EQUAL_MY_IP: Field equal to IP address of the PC
- NOTEQUAL_MY_IP: Field not equal to IP address of the PC
The value display mode allows displaying fields according to their type (example : "hexa-byte split" for MAC address)
它是什么? 并且它提供什么我? 这是一个 LnS 的 plugin ; 它增加延长的能力为规则创作, 您可能过滤在未加工级(最低的水平可能), 过滤器由任何东西在整个小包倒栽跳水... 这些是基本什么我们必须知道; --- 一个未加工的规则被定义: - 规则名字- 规则描述- 规则适用的小包方向: 入站, 向外去或两个- 1 个到10 个领域 审阅因特网过滤的比赛规则的以太网小包如果所有规则的领域匹配对应的小包调遣。 领域被定义:
- 领域标识符: 0 到9
- 领域大小: 1 个到6 个字节
- 领域垂距类型: 以太网, IP, TCP
- 领域垂距为入站小包(相对垂距型)
- 领域垂距为向外去小包(相对垂距型)
- 领域标准- 领域Value1 、Value2 和面具。
关于领域垂距类型: 如果垂距型是以太网, 领域垂距(入站或向外去) 开始"0 字节" 在以太网小包第一个字节以后。
如果垂距型是IP, 领域垂距(入站或向外去) 开始"18 个字节" 在以太网小包第一个字节以后。
如果垂距型是TCP, 领域垂距(入站或向外去) 开始"34+4+IHL 字节" 在以太网小包第一个字节以后。(IHL = IP 标头长度) 。
领域标准也许是这些的当中一个:
- NA: 不可适用的领域(缺省)
- EQUAL_VALUE1: 领域均等对Value1
- NOTEQUAL_VALUE1: 领域不相等与Value1
- RANGE_IN: 领域是在Value1:Value2 范围
- RANGE_OUT: 领域是在Value1:Value2 范围之外
- MASK_VALUE1: (领域和面具) 均等对Value1
- NOTMASK_VALUE1: (领域和面具) 不是均等对Value1
- RANGE_IN_REV: 领域是在Value1:Value2 范围(反向字节次序)
- RANGE_OUT_REV: 领域是超出Value1:Value2 范围(反向字节次序)
- EQUAL_VALUE1OR2: 领域均等对Value1 或Value2
- NOTEQUAL_VALUE1AND2: 领域与Value1 和Value2 不同
- EQUAL_MY_IP: 领域相等与个人计算机的IP 地址
- NOTEQUAL_MY_IP: 领域不相等与个人计算机的IP 地址 价值显示方式允许显示域根据他们的型(例子: "六字节被分裂" 为机器地址)
(未完) 有时间再整理
P.S. 转贴请注明 卡饭虾米仔原创http://bbs.kafan.cn/viewthread.php?tid=94699&highlight=lns
[ 本帖最后由 糖衣炮弹 于 2008-5-5 12:45 编辑 ] |
|