| To: | Patrick McHardy <kaber@xxxxxxxxx> |
|---|---|
| Subject: | Possible ip_defrag DoS ? |
| From: | Harald Welte <laforge@xxxxxxxxxxxxx> |
| Date: | Sun, 16 Feb 2003 21:11:54 +0100 |
| Cc: | Don Cohen <don-netf@xxxxxxxxxxxxxxxx>, netfilter-devel@xxxxxxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx |
| In-reply-to: | <3E4F8660.5020409@xxxxxxxxx> |
| Mail-followup-to: | Harald Welte <laforge@xxxxxxxxxxxxx>, Patrick McHardy <kaber@xxxxxxxxx>, Don Cohen <don-netf@xxxxxxxxxxxxxxxx>, netfilter-devel@xxxxxxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx |
| References: | <20030215232635.25928.78900.Mailman@kashyyyk> <15950.60635.389199.836425@xxxxxxxxxxxxxxxx> <3E4F0881.70302@xxxxxxxxx> <15951.10496.914173.716313@xxxxxxxxxxxxxxxx> <3E4F8660.5020409@xxxxxxxxx> |
| Sender: | netdev-bounce@xxxxxxxxxxx |
| User-agent: | Mutt/1.3.28i |
On Sun, Feb 16, 2003 at 01:38:56PM +0100, Patrick McHardy wrote: > inerestingly, it seems linux defragmentation is vulnerable to dos attack. > the evictor (called before defragmentation) just kills the oldest entry > of each hash slot, starting with 0 until memory is below > sysctl_ipfrag_low_thresh. by sending enough fragments > (>sysctl_ipfrag_high_thresh) which hash to the highest bucket you can > stop reassembly of valid packets. I'm forwarding this (from netfilter-devel) to the linux networking developers at netdev@xxxxxxxxxxxx If your assumption is valid, they might want to have a look at this... thanks. > Patrick -- - Harald Welte <laforge@xxxxxxxxxxxxx> http://www.netfilter.org/ ============================================================================ "Fragmentation is like classful addressing -- an interesting early architectural error that shows how much experimentation was going on while IP was being designed." -- Paul Vixie
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | IPsec in linux-2.5.61, Kazunori MIyazawa |
|---|---|
| Next by Date: | e100 in 2.5.59 through 2.5.61, James H. Cloos Jr. |
| Previous by Thread: | IPsec in linux-2.5.61, Kazunori MIyazawa |
| Next by Thread: | e100 in 2.5.59 through 2.5.61, James H. Cloos Jr. |
| Indexes: | [Date] [Thread] [Top] [All Lists] |