Re: packets with syn/fin vs pf_norm.c

From: fooler (fooler_at_skyinet.net)
Date: 07/06/05

  • Next message: Garrett Wollman: "Re: packets with syn/fin vs pf_norm.c"
    To: "Jesper Wallin" <jesper@hackunite.net>, Dag-Erling Smørgrav <des@des.no>
    Date: Wed, 6 Jul 2005 14:11:40 +0800
    
    

    ----- Original Message -----
    From: "Dag-Erling Smørgrav" <des@des.no>
    To: "Jesper Wallin" <jesper@hackunite.net>
    Cc: <freebsd-security@freebsd.org>; "Darren Reed"
    <avalon@caligula.anu.edu.au>
    Sent: Wednesday, July 06, 2005 1:39 PM
    Subject: Re: packets with syn/fin vs pf_norm.c

    > The TCP_DROP_SYNFIN option should be removed; it has long outlived its
    > original purpose (which was to prevent nmap identification of IRC
    > servers which didn't run ipfw for performance reasons, back in the 3.0
    > days)

    i vote not to remove because it just an option there whether you want it or
    not for added protection for OS fingerprinting...

    standard tcp is the most rampant used than t/tcp and most (or all) tcp
    modules are not combining syn + fin flag in a tcp datagram for normal tcp
    transaction...

    fooler.

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Garrett Wollman: "Re: packets with syn/fin vs pf_norm.c"

    Relevant Pages

    • Re: [FATAL] Kerberos does not have a ticket for <any of my servers>
      ... they should be using TCP. ... Most of the Local servers I've been able to get the Kerberos to pass by ... I'm rebooting the Exchange 2003 Server now to get it update as well as the ...
      (microsoft.public.win2000.active_directory)
    • Re: Updates
      ... forces the max tcp window size to 64k. ... This turns off Receive Window Auto-Tuning, and prevents vista ... slow (but only when communicating with the two 2k3 sp2 servers). ...
      (microsoft.public.cert.exam.mcse)
    • new server 2003 slow login NOT a DNS problem
      ... we have a remote site that had been using Windows 2000 servers until ... UDP:138 ... TCP:445 ...
      (microsoft.public.windows.server.general)
    • Re: major DNS hiccup
      ... Some DNS queries are done via UDP, others via TCP, so firewalling TCP is ... I see traffic passing both ways (all udp, no tcp, incidentally), and all with correct checksums, and nothing being blocked. ... What I get is nameserver reply packets from assorted unrelated servers with defects in them - either no answer record but with the question returned to me, or no answer /and/ no question. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Automatic Updates security concern
      ... If those servers are not configured to support SSL ... on tcp 443 then the update clients will be forced to use tcp ... Is there any way of setting the AU repository so it never uses https (tcp ... clients end up ...
      (microsoft.public.security)