Re: No more DoS

From: Michael Peddemors (michael@linuxmagic.com)
Date: Thu Dec 21 2000 - 23:20:06 EST


> Furthermore, it also cannot work because it makes retransmissions
> of the SYN/ACK very non-workable. I suppose his TCP stack just hacks
> around this by just waiting for the original client SYN to get
> retransmitted or something like this. I question whether that can
> even work reliably.

Be interesting to see his response, but in truth, do we care if it gets
retransmitted?? When it does, it does...

> I think not holding onto any state for an incoming SYN is nothing but
> a dream in any serious modern TCP implementation. It can be reduced,
> but not eliminated. The former is what most modern stacks have done
> to fight these problems.

A dream, maybe .... but hey so were most things that we now take for granted..
Worth kicking around a bit tho...

--------------------------------------------------------
Michael Peddemors - Senior Consultant
Unix Administration - WebSite Hosting
Network Services - Programming
Wizard Internet Services http://www.wizard.ca
Linux Support Specialist - http://www.linuxmagic.com
--------------------------------------------------------
(604) 589-0037 Beautiful British Columbia, Canada
--------------------------------------------------------
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sat Dec 23 2000 - 21:00:30 EST