Re: use keep state(strict) to mitigate tcp issues?

From: Peter Jeremy (peterjeremy_at_optushome.com.au)
Date: 04/26/04

  • Next message: jayanth: "Re: [Full-Disclosure] IETF Draft - Fix for TCP vulnerability (fwd)"
    Date: Mon, 26 Apr 2004 19:13:32 +1000
    To: Mipam <mipam@ibb.net>
    
    

    On Mon, Apr 26, 2004 at 09:18:05AM +0200, Mipam wrote:
    >I have no statistics and didnt check it out more closely, but in practise,
    >let's say just daily life, in how many connecties would packets be
    >arriving out of order?

    My ISP speed-limits my connection if I exceed my monthly data volume.
    I'm not sure how they do the speed limiting but it seems to fairly
    consistently result in the last data packet arriving after the FIN
    packet. I don't have statistics for when my connection is running
    normally.

    Peter
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: jayanth: "Re: [Full-Disclosure] IETF Draft - Fix for TCP vulnerability (fwd)"

    Relevant Pages

    • Re: iptables tcp-logged ACK PSH
      ... > the following in my logs: ... some sort of packet is arriving that appears to be ... More likely the connection is closing ...
      (comp.os.linux.security)
    • Re: peer to peer messaging
      ... attempts to open a connection to port 80 of the server at that IP address. ... For example a packet from my machine might have source IP ... Packets from the sever to my laptop would have those reversed. ...
      (comp.lang.java.programmer)
    • Re: IPFW Dynamic Rules
      ... > So if the dynamic rule has the same behaviour as the origination ... > rule on the same port with the same protocol, ... If client sends UDP query to DNS on your machine, you get the packet: ... is deleted after connection is inactive for some time. ...
      (FreeBSD-Security)
    • [NEWS] Cisco PIX TCP Connection DoS
      ... Get your security news from a reliable source. ... By crafting a special TCP packet and sending it to a vulnerable Cisco PIX, ... embryonic connection open until the embryonic connection timeout which is ...
      (Securiteam)
    • Re: Nmap questions concering my router
      ... that may have to be fetched) is downloaded as one connection. ... >> all addresses (and may listen using just one interface to receive all ... sends packets to the correct protocol driver ... wire to an IP packet, and hands this to the IP driver which strips off ...
      (comp.security.firewalls)