Re: Better than SYNcookies?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> So is he right, is his solution better than SYNcookies and there is
> something to be learned from his solution? Or does someone need to take
> him to school on the issue.

He isnt preserving the negotiated TCP MSS.

Other issues:

- If his ISN is the ip address then its a constant which is far worse than 
random and also usable for replay attacks 

[ie I dial up log the cookie, wait for you to get the same line - and I can
 collect the dialup rack over time]

Alan





-
: send the line "unsubscribe linux-net" in
the body of a message to majordomo@vger.kernel.org


[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux 802.1Q VLAN]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Git]     [Bugtraq]     [Yosemite News and Information]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux PCI]     [Linux Admin]     [Samba]

  Powered by Linux