From: Denys Fedoryshchenko <denys@visp.net.lb>
To: <netdev@vger.kernel.org>
Subject: SYN attack, with FIN flag set
Date: Sat, 03 Dec 2011 00:29:59 +0200 [thread overview]
Message-ID: <1755dc626dee301261ef4fe4cd66fd47@visp.net.lb> (raw)
Hi
Recently i started to get SYN attacks, and managed them.
syncookies didn't helped, here is "perf report" info:
- 26.89% swapper [kernel.kallsyms] [k] _raw_spin_lock
- _raw_spin_lock
- 94.97% tcp_v4_rcv
ip_local_deliver_finish
ip_local_deliver
ip_rcv_finish
ip_rcv
__netif_receive_skb
process_backlog
net_rx_action
__do_softirq
call_softirq
do_softirq
+ irq_exit
But then i got attack that made server to choke and bypassed "--syn"
rule, and i was surprised, that stack are handling invalid combination
of flags, SYN+FIN.
Is it valid behaviour?
in tcp_input.c, tcp_rcv_state_process(), it just does check for rst (to
discard), but maybe packet with fin set should be discarded too?
From http://www.whitehats.ca/main/members/Seeker/seeker_tcp_header/
SYN FIN is probably the best known illegal combination. Remember that
SYN is used to start a connection, while FIN is used to end an existing
connection. It is nonsensical to perform both actions at the same time.
Many scanning tools use SYN FIN packets, because many intrusion
detection systems did not catch these in the past, although most do so
now. You can safely assume that any SYN FIN packets you see are
malicious.
---
System administrator
Denys Fedoryshchenko
Virtual ISP S.A.L.
next reply other threads:[~2011-12-02 22:30 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-12-02 22:29 Denys Fedoryshchenko [this message]
2011-12-03 7:27 ` SYN attack, with FIN flag set Eric Dumazet
2011-12-03 7:55 ` Eric Dumazet
2011-12-03 8:18 ` Denys Fedoryshchenko
2011-12-03 8:53 ` Eric Dumazet
2011-12-03 9:03 ` Michael Tokarev
2011-12-03 9:07 ` Denys Fedoryshchenko
2011-12-03 9:41 ` Eric Dumazet
2011-12-03 10:02 ` Eric Dumazet
2011-12-03 18:40 ` Denys Fedoryshchenko
2011-12-04 6:26 ` David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1755dc626dee301261ef4fe4cd66fd47@visp.net.lb \
--to=denys@visp.net.lb \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.