| To: | Willy Tarreau <willy@xxxxxxxxx> |
|---|---|
| Subject: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.) |
| From: | Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> |
| Date: | Sun, 12 Jun 2005 20:30:20 +1000 |
| Cc: | davem@xxxxxxxxxxxxx, xschmi00@xxxxxxxxxxxxxxxxxx, alastair@xxxxxxxxxxxx, linux-kernel@xxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx |
| In-reply-to: | <20050612083409.GA8220@xxxxxxxxxxxxxxxx> |
| References: | <20050611074350.GD28759@xxxxxxxxxxxxxxxx> <E1DhBic-0005dp-00@xxxxxxxxxxxxxxxxxxxxxxxx> <20050611195144.GF28759@xxxxxxxxxxxxxxxx> <20050612081327.GA24384@xxxxxxxxxxxxxxxxxxx> <20050612083409.GA8220@xxxxxxxxxxxxxxxx> |
| Sender: | netdev-bounce@xxxxxxxxxxx |
| User-agent: | Mutt/1.5.9i |
On Sun, Jun 12, 2005 at 10:34:09AM +0200, Willy Tarreau wrote: > > > Sorry but this patch is pointless. If I wanted to prevent you from > > connecting to www.kernel.org 80 and I knew your source port number > > I'd be directly sending you fake SYN-ACK packets which will kill > > your connection immediately. > > Only if your ACK was within my SEQ window, which adds about 20 bits of > random when my initial window is 5840. You would then need to send one > million times more packets to achieve the same goal. Nope, no sequence validity check is made on the SYN-ACK. -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt |
| Previous by Date: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
|---|---|
| Next by Date: | Re: testing techniques to confirm the effectiveness of changes made to sch_gred.c, Thomas Graf |
| Previous by Thread: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
| Next by Thread: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
| Indexes: | [Date] [Thread] [Top] [All Lists] |