Re: syn DDoS attack solution

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



R. DuFresne wrote:

On Fri, 1 Jun 2007, Martijn Lievaart wrote:

An connection is in the ESTABLISHED state once a packet has been seen. So once the SYN is seen, the state is ESTABLISHED.



No, it is in state "new" with a mere syn sent.

You have to specify whether you are talking about the TCP connection
status or the conntrack status.  A mere SYN is sufficient to make an
ESTABLISHED status in conntrack.  If that were not true, then when
I send a TCP SYN packet the SYN/ACK would never make it back through
my firewall.

--
Bob Nichols     "NOSPAM" is really part of my email address.
                Do NOT delete it.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux