From mboxrd@z Thu Jan 1 00:00:00 1970 From: Henrik Nordstrom Subject: Re: Security flaw in Stateful filtering ?????? Date: Thu, 6 Jun 2002 21:43:31 +0200 Sender: netfilter-devel-admin@lists.samba.org Message-ID: <200206062143.31347.hno@marasystems.com> References: <3CFFAF5D.4010103@cs.auc.dk> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 8bit Return-path: To: netfilter-devel@lists.samba.org, Emmanuel Fleury In-Reply-To: <3CFFAF5D.4010103@cs.auc.dk> Errors-To: netfilter-devel-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Unsubscribe: , List-Archive: List-Id: netfilter-devel.vger.kernel.org Emmanuel Fleury wrote: > So, what are the INVALID packets ????? Packets where it is impossible to identify a session key to use when matching reply packets as belonging to the same session. This is mostly malformed packets. I think RST of a non-existing session also classifies as INVALID, but I am not sure.. and in reality does not matter much.. Regards Henrik