Re: linux kernel TCP, network connections and iptables

From: kuznet@ms2.inr.ac.ru
Date: Fri Sep 08 2000 - 11:12:20 EST


Hello!

> Well, it looks like you're getting hit with stream.c or raped.c and what
> I'm passing on is just what I picked up from a CERT guy at Usenix. He
> claimed that stream.c worked by exploiting a long path through the kernel

He just said a crap. All the discussion around stream.c is banal
ether pollution.

> to bring the machine to its knees.

The same happens if you send any kind of packets. F.e. nice
method uncatchable by any firewall is to open good TCP connection
and to feed it with single byte packets. 8)

The only way to fight this is not to attach machine to fast network
or to slow down network artificially. 8)

Alexey
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Fri Sep 15 2000 - 21:00:10 EST