You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求技术指导:用Python编写脚本阻止DoS攻击(校园项目)

Hey there! Let's work through this problem since you're tackling a campus project to block your custom DoS script's attacks—super practical stuff. I’ll break down how to handle IP/port/MAC blocking with Python, especially since you ran into issues with iptables libraries across Python 2.7, 3.4, and 3.6.

First: Fixing the IPTables Compatibility Headache

If you struggled installing python-iptables (the common library for this), it’s likely due to version gaps (Python 2.7’s library support is pretty limited now) or permission issues. A far more universal workaround is to directly call system iptables commands from your Python script—no extra libraries needed, and it works across all the Python versions you’re using. Just remember: you must run the script with root/sudo privileges, since iptables is a system-level tool that requires admin access.


Practical Blocking Scripts (IP/Port/MAC)

Below are tested, version-compatible scripts that use system iptables calls.

1. Block a Specific IP Address

If you know the source IP of your DoS script, you can drop all incoming traffic from it:

import subprocess

def block_ip(ip_address):
    # Add iptables rule to drop traffic from the target IP
    try:
        subprocess.run([
            'iptables', '-A', 'INPUT', '-s', ip_address, '-j', 'DROP'
        ], check=True)
        print(f"✅ Successfully blocked IP: {ip_address}")
    except subprocess.CalledProcessError:
        print(f"❌ Failed to block {ip_address}—check permissions or IP format")

# Example usage
block_ip("192.168.1.100")

To unblock the IP later, swap -A (append rule) with -D (delete rule):

def unblock_ip(ip_address):
    subprocess.run([
        'iptables', '-D', 'INPUT', '-s', ip_address, '-j', 'DROP'
    ], check=True)
    print(f"✅ Successfully unblocked IP: {ip_address}")

2. Block a Target Port

If your DoS script targets a specific port (e.g., 80 or 8080), you can block all traffic to that port, or restrict it to a specific IP:

def block_port(port):
    # Block all incoming traffic to the target port
    subprocess.run([
        'iptables', '-A', 'INPUT', '--dport', str(port), '-j', 'DROP'
    ], check=True)
    print(f"✅ Successfully blocked port: {port}")

# Block only a specific IP accessing the port
def block_ip_port(ip_address, port):
    subprocess.run([
        'iptables', '-A', 'INPUT', '-s', ip_address, '--dport', str(port), '-j', 'DROP'
    ], check=True)
    print(f"✅ Blocked {ip_address} from accessing port {port}")

Again, use -D instead of -A to remove these rules later.

3. Block a MAC Address

MAC blocking only works for devices on the same local network (since MAC addresses are replaced across routers), but it’s useful for LAN-based attacks:

def block_mac(mac_address):
    # Ensure the iptables mac module is loaded (most systems have this by default)
    subprocess.run([
        'iptables', '-A', 'INPUT', '-m', 'mac', '--mac-source', mac_address, '-j', 'DROP'
    ], check=True)
    print(f"✅ Successfully blocked MAC address: {mac_address}")

Make sure the MAC is formatted correctly (e.g., 00:11:22:33:44:55).


Critical Notes for Your Project
  • Permissions: Always run your script with sudo (e.g., sudo python block_dos.py)—without root access, iptables will throw permission errors.
  • Rule Persistence: The rules above disappear after a system reboot. To save them permanently (on Debian/Ubuntu), install iptables-persistent and run iptables-save > /etc/iptables/rules.v4.
  • Python 2.7/3.4 Compatibility: subprocess.run() works in Python 3.5+. For older versions, use subprocess.call() instead—it has nearly identical syntax:
    # Python 2.7/3.4 compatible version
    subprocess.call(['iptables', '-A', 'INPUT', '-s', '192.168.1.100', '-j', 'DROP'])
    
  • Test First: Before deploying, replace DROP with LOG to verify the rule is targeting the right traffic (check logs at /var/log/syslog on Linux). Switch to DROP once you’re confident.

Backup Option: No IPTables? Use Python Sockets

If for some reason you can’t use iptables (e.g., non-Linux environment), you can use Python’s socket library to filter traffic directly. This is less efficient than iptables, but works for small-scale testing:

import socket
from time import time

def listen_and_block(port):
    sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
    sock.bind(('0.0.0.0', port))
    sock.listen(5)
    blocked_ips = set()
    ip_requests = {}

    while True:
        conn, addr = sock.accept()
        ip = addr[0]
        
        if ip in blocked_ips:
            conn.close()
            continue
        
        # Simple DoS detection: block IPs with >10 requests in 5 seconds
        current_time = time()
        ip_requests[ip] = ip_requests.get(ip, []) + [current_time]
        # Remove old requests
        ip_requests[ip] = [t for t in ip_requests[ip] if current_time - t < 5]
        
        if len(ip_requests[ip]) > 10:
            blocked_ips.add(ip)
            print(f"⛔ Blocked DoS source: {ip}")
        
        conn.close()

# Example: Monitor port 8080
listen_and_block(8080)

内容的提问来源于stack exchange,提问作者Team P.N.O.P

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:48:56