Re: packets with syn/fin vs pf_norm.c

From: Jesper Wallin (jesper_at_ifconfig.se)
Date: 07/03/05

  • Next message: Garrett Wollman: "Re: packets with syn/fin vs pf_norm.c"
    Date: Sun, 03 Jul 2005 23:56:39 +0200
    To: Garrett Wollman <wollman@csail.mit.edu>
    
    

    Garrett Wollman wrote:

    ><<On Sun, 03 Jul 2005 00:06:37 +0200, Jesper Wallin <jesper@www.hackunite.net> said:
    >
    >
    >
    >>First of all, I know that not dropping SYN/FIN isn't really a big deal, it
    >>just makes no sense. But since it doesn't make any sense, I don't see
    >>the reason why not to discard them.
    >>
    >>
    >
    >Perhaps because you are under the erroneous impression that such
    >packets are nonsensical.
    >
    >-GAWollman
    >
    That might be the case yeah.. Yet, if I have TCP_DROP_SYNFIN in my
    kernel and
    sysctrl net.inet.tcp.drop_synfin set to 1, shouldn't it drop all SYN/FIN
    packets no
    matter how my firewall is configured?

    Best regards,
    Jesper Wallin
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Garrett Wollman: "Re: packets with syn/fin vs pf_norm.c"

    Relevant Pages

    • packets with syn/fin vs pf_norm.c
      ... > the reason why not to discard them. ... packets are nonsensical. ... To unsubscribe, ...
      (FreeBSD-Security)
    • Re: Strange attack question - seems udp
      ... Thanks for explainning the reason for udp ports not appearing in the ... Well the Cisco 3750 is the gateway for my clients and not the ... >>that the length of the packets is always 1500. ...
      (Incidents)
    • Re: Boyfriend will have a surprise
      ... Six packets of treats now in the garbage bin. ... It's not a reason for a refund. ... Sometimes you are then allowed to take it back and get equivalent money voucher to spend at the same store. ...
      (rec.pets.cats.anecdotes)
    • posible latency issues in seq_read
      ... It appears that for some reason the networking softirq is not being handled in a timely fashion, which means that the rx ring buffer fills up and packets overflow. ... While we're in the syscall we cannot run the softirqd thread, and so the rx buffer is not being cleaned. ...
      (Linux-Kernel)
    • IP Options filtering
      ... This seems to be the last "black area" for me in the ISA 2004 configuration. ... packets with the selected IP options” ... What is a possible reason to prohibit IP options? ... situations in which I should change the default settings? ...
      (microsoft.public.isa.configuration)