From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Jet" Subject: Re: does the ip_conntrack subjected to DOS attack??? Date: Tue, 5 Nov 2002 11:37:22 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001701c2847c$a7cf5870$0bc8c80a@dolphin> References: <002401c28193$9fcbbba0$1801010a@demo> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0014_01C284BF.B4FAF200" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Ben Tan , a This is a multi-part message in MIME format. ------=_NextPart_000_0014_01C284BF.B4FAF200 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Just want to check with you on how much RAM do you have? What is the max = table size (cat /proc/sys/net/ipv4/ip_conntrack_max) and if possible = what is the size of the connection table before it crashes? I have the same problem too on kernel 2.4.18-xfs. What is yours? I = believe the bug is called OOM (out-of-memory). .//Jet ----- Original Message -----=20 From: Ben Tan=20 To: a=20 Sent: Friday, November 01, 2002 6:44 PM Subject: does the ip_conntrack subjected to DOS attack??? hi, it seems that once the ip_conntrack table is being filled up, the = system will crash.=20 Does it means that it is very vulnerable to DOS attack? I have performed a port scan using nmap on my box, and it is able = to scan alot of ports being opened? How come this happened? I only allow = established,related tcp packets and tcp port 22 New on INPUT to the box? = The default policy is DROP. The result is=20 port 22 open=20 port 80 open Why it is so? Pls advise. Thanks in advanced. ben =20 ------=_NextPart_000_0014_01C284BF.B4FAF200 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Just want to check with you on how much = RAM do you=20 have? What is the max table size (cat = /proc/sys/net/ipv4/ip_conntrack_max) =20 and if possible what is the size of the connection table before it=20 crashes?
 
I have the same problem too on kernel = 2.4.18-xfs.=20 What is yours? I believe the bug is called OOM = (out-of-memory).
 
 
.//Jet
----- Original Message -----
From:=20 Ben=20 Tan
To: a
Sent: Friday, November 01, 2002 = 6:44=20 PM
Subject: does the ip_conntrack = subjected=20 to DOS attack???

hi,
    it seems that once = the=20 ip_conntrack table is being filled up, the system will crash. =
 
    Does it means that = it is very=20 vulnerable to DOS attack?
 
    I have performed = a port=20 scan using nmap on my box, and it is able to scan alot of ports being = opened?=20 How come this happened? I only allow established,related tcp packets=20 and tcp port 22 New on INPUT to the box? The default policy is=20 DROP.
 
    The result is =
    port 22 open =
    port 80 = open
 
Why it is so? Pls advise. Thanks in=20 advanced.
 
ben
    =  
 
   =20
------=_NextPart_000_0014_01C284BF.B4FAF200--