I experienced another problem after compiling the ipt_string.c
Now i get a Kernel PANIC!
I set up a rule for dropping all icmp requests coming from a speacial host with hex-string-matching
"7f656c66". Now when I am sending this hex-string via "ping" from the host, my Firewall get's a Kernel PANIC.
The PANIC accures when ipt_do_table is in stack. So does anyone know this error? I have no idea how to deal with it. The module is properly loaded.
Perhaps there is another module missing?

The rule:
iptalbes -I INPUT -m string --hex-string 7f656c66 -p icmp -s vvv.xx.y.zz -j DROP


.. you could call it a "Ping of death" - but I don't like that. Kernel: 2.6.12.2; iptables: 1.3.3


Unable to handle kernel NULL pointer

Oops: 0000 [#1]
EIP: 0060
EFLAGS: 00010206
EIP is at rest_init 0x3feffd6c/ox28
Process swapper (pid:0
Call Trace:

ipt_do_table
ip_local_deliver_finish
ipt_hook
nf_iterate
ip_local_deliver_finish
ip_local_deliver
ip_local_deliver_finish
ip_rcv
netif_recieve_skb
process_backlog
net_rx_action
_do_softirq
irq_exit
do_IRQ
common_interrupt
default_idle
default_idle
cpu_idle
start_kernel
Code: Bad EIP value
Kernel PANIC - not syncing: Fatal exception in interrupt