Tcpkill
From Wikipedia, the free encyclopedia
Tcpkill is a network utility program that can be used to terminate connections to or from a particular host, network, port, or combination of all. These programs take standard Berkeley Packet Filter (BPF) filters. This can be used for both port mirroring and ARP spoofing.[1]
To prevent any connections to the host www.google.com use this command:
- /usr/sbin/tcpkill −9 host www.google.com
The computer that is attempting to go to that site will be blocked from that site only, but can surf any other site. It is a good idea to either redirect the output into nothingness ( > 2>/dev/null 1>/dev/null) or into a file for later analysis (> file.tcpkill ). By default, it will redirect output to the console.
More hosts can be specified with the command:
- /usr/sbin/tcpkill −9 host www.google.com and host www.yahoo.com
To block well−known ports e.g., napster (port 8888 and port 6699) or gnutella (port 6346), the command:
- /usr/sbin/tcpkill −9 port 8888 and port 6699
or
- /usr/sbin/tcpkill −9 port 6346
DoS with tcpkill
Tcpkill can be used to create a DoS attack within a WAN or LAN, and this can be done by using a sniffer like dsniff or tcpdump to look at the packets that are being transmitted and to pick a target that you want to deny service. Assume the target has been identified as 192.168.100.38, a simple command like:
tcpkill -9 host 192.168.100.38
will kill all outgoing tcp packets (TCP segment) between the target and the rest of the network. Prior to the attack the target can receive packets from the rest of the network.