Re: REJECTing ident requests (was: FTP problems)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le ven 28/02/2003 à 16:13, Maciej Soltysiak a écrit :
> > Maybe because RFC says that a SYN on a closed port must be replied with
> > RST, and not ICMP port unreachable...
> It is true but by sending ICMP port unreach. you inform the second
> party's tcp stack that the port is unreachable, which should cause the
> stack to inform the application that there is a problem. Maybe the
> application (the mail daemon) was not handling this type of error.

It is probably the case.

> Properly written code should react for TCP RSTs and all other ICMP error
> messages, and other error conditions.

True.

-- 
Cédric Blancher  <blancher@cartel-securite.fr>
Consultant en sécurité des systèmes et réseaux  - Cartel Sécurité
Tél: +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99
PGP KeyID:157E98EE  FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux