OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: pwb on March 11, 2025, 02:08:06 PM

Title: Detect and block TCP Copy, possible?
Post by: pwb on March 11, 2025, 02:08:06 PM
Is it possible to detect and block TCPCopy traffic?
Title: Re: Detect and block TCP Copy, possible?
Post by: meyergru on March 11, 2025, 04:20:18 PM
As TCPCopy apparently only captures and replicates arbitrary IP traffic to divert somewhere else by just rewriting address information with no application-specific encapsulation, there is obviously nothing that would make this diverted traffic identifiable or discernible from direct traffic hitting the target.