iptables string matching

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
az1441
DD-WRT Novice


Joined: 04 Nov 2017
Posts: 13

PostPosted: Fri Jun 11, 2021 18:53    Post subject: iptables string matching Reply with quote
Hi guys - been gone for quite a while and a lot of my searches have turned up ambiguous.

My question is - does iptables compiled witb DDWRT out of the box work with string matching?

for the life of me i can ngrep a pattern and see its output with it or tcpdump - but every iptables rule i build will not match it

this is one of my rules

iptables -I FORWARD -m string --string "scratch"’ --algo bm -j DROP


which in the tables list is:

Chain FORWARD (policy ACCEPT)
num target prot opt source destination
2 DROP all -- anywhere anywhere STRING match "|e2809c73637261746368e2809d|" ALGO name bm TO 65535

i hit a non secure site over 80 like i said - ngrep sees it...

iptables doesnt match it

is this typical?
Sponsor
Wildlion
DD-WRT Guru


Joined: 24 May 2016
Posts: 1415

PostPosted: Fri Jun 11, 2021 21:50    Post subject: Reply with quote
Have you tried it on the command line? But I do not think it works.

You may also have to provide what build and model you are on, because obviously a 4mb build will have less things than the full build. I know that on the X86 build it seems to have a much fuller iptables than on the routers.

You could also install entware and the full iptables.
az1441
DD-WRT Novice


Joined: 04 Nov 2017
Posts: 13

PostPosted: Sat Jun 12, 2021 3:54    Post subject: Reply with quote
I am an idiot and was pasting from another app that was jacking up my syntax.. it DOES in fact work...

thanks Wild for the reply sir

Wildlion wrote:
Have you tried it on the command line? But I do not think it works.

You may also have to provide what build and model you are on, because obviously a 4mb build will have less things than the full build. I know that on the X86 build it seems to have a much fuller iptables than on the routers.

You could also install entware and the full iptables.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12887
Location: Netherlands

PostPosted: Sat Jun 12, 2021 6:51    Post subject: Reply with quote
You do know it does not work on https as that is encrypted?

So in real life it is of less use nowadays Sad

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
az1441
DD-WRT Novice


Joined: 04 Nov 2017
Posts: 13

PostPosted: Sun Jun 13, 2021 17:27    Post subject: Reply with quote
Yeah im stupid but not that stupid

its a udp random port packet
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6868
Location: Romerike, Norway

PostPosted: Sun Jun 13, 2021 18:29    Post subject: Reply with quote
Vanlig navn (CN) forum.dd-wrt.com
Organisasjon (O) <Ikke del av sertifikat>
Organisasjonsenhet (OU) <Ikke del av sertifikat>
Vanlig navn (CN) R3
Organisasjon (O) Let's Encrypt
Organisasjonsenhet (OU) <Ikke del av sertifikat>


Let's Encrypt is known to hand out free certificates.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum