| To: | Willy Tarreau <willy@xxxxxxxxx> |
|---|---|
| Subject: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.) |
| From: | Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> |
| Date: | Sun, 12 Jun 2005 23:50:18 +1000 |
| Cc: | davem@xxxxxxxxxxxxx, xschmi00@xxxxxxxxxxxxxxxxxx, alastair@xxxxxxxxxxxx, linux-kernel@xxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx |
| In-reply-to: | <20050612134725.GB8951@alpha.home.local> |
| References: | <20050611195144.GF28759@alpha.home.local> <20050612081327.GA24384@gondor.apana.org.au> <20050612083409.GA8220@alpha.home.local> <20050612103020.GA25111@gondor.apana.org.au> <20050612114039.GI28759@alpha.home.local> <20050612120627.GA5858@gondor.apana.org.au> <20050612123253.GK28759@alpha.home.local> <20050612131323.GA10188@gondor.apana.org.au> <20050612133349.GA6279@gondor.apana.org.au> <20050612134725.GB8951@alpha.home.local> |
| Sender: | netdev-bounce@xxxxxxxxxxx |
| User-agent: | Mutt/1.5.9i |
On Sun, Jun 12, 2005 at 03:47:25PM +0200, Willy Tarreau wrote: > > Yes, but only if there's an ACK and the ACK is exactly equal to snd_next, > so the connection will survive. Sorry I wasn't thinking straight. > > > My point is that there are many ways to kill TCP connections in ways > > similar to what you proposed initially so it isn't that special. > > No, there are plenty of ways to kill TCP connections when you can guess > the window (which is more and more easy thanks to window scaling). But > I have yet found no way to kill a TCP session without this info, except > by exploiting the simultaneous connect feature. I still stand by this point though. The most obvious thing I can think of right now is to change your attack to simply connect to kernel.org's webserver first from source port 10000. That will cause the real SYN packet to fail the sequence number check. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt |
| Previous by Date: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
|---|---|
| Next by Date: | [PATCH] Ensure to use icmpv6_socket in non-preemptive context., YOSHIFUJI Hideaki / 吉藤英明 |
| Previous by Thread: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
| Next by Thread: | Re: [PATCH] fix small DoS on connect() (was Re: BUG: Unusual TCP Connect() results.), Willy Tarreau |
| Indexes: | [Date] [Thread] [Top] [All Lists] |