* does the ip_conntrack subjected to DOS attack???
@ 2002-11-01 10:44 Ben Tan
2002-11-05 3:37 ` Jet
0 siblings, 1 reply; 2+ messages in thread
From: Ben Tan @ 2002-11-01 10:44 UTC (permalink / raw)
To: a
[-- Attachment #1: Type: text/plain, Size: 536 bytes --]
hi,
it seems that once the ip_conntrack table is being filled up, the system will crash.
Does it means that it is very vulnerable to DOS attack?
I have performed a port scan using nmap on my box, and it is able to scan alot of ports being opened? How come this happened? I only allow established,related tcp packets and tcp port 22 New on INPUT to the box? The default policy is DROP.
The result is
port 22 open
port 80 open
Why it is so? Pls advise. Thanks in advanced.
ben
[-- Attachment #2: Type: text/html, Size: 1704 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: does the ip_conntrack subjected to DOS attack???
2002-11-01 10:44 does the ip_conntrack subjected to DOS attack??? Ben Tan
@ 2002-11-05 3:37 ` Jet
0 siblings, 0 replies; 2+ messages in thread
From: Jet @ 2002-11-05 3:37 UTC (permalink / raw)
To: Ben Tan, a
[-- Attachment #1: Type: text/plain, Size: 1058 bytes --]
Just want to check with you on how much RAM do you have? What is the max table size (cat /proc/sys/net/ipv4/ip_conntrack_max) and if possible what is the size of the connection table before it crashes?
I have the same problem too on kernel 2.4.18-xfs. What is yours? I believe the bug is called OOM (out-of-memory).
.//Jet
----- Original Message -----
From: Ben Tan
To: a
Sent: Friday, November 01, 2002 6:44 PM
Subject: does the ip_conntrack subjected to DOS attack???
hi,
it seems that once the ip_conntrack table is being filled up, the system will crash.
Does it means that it is very vulnerable to DOS attack?
I have performed a port scan using nmap on my box, and it is able to scan alot of ports being opened? How come this happened? I only allow established,related tcp packets and tcp port 22 New on INPUT to the box? The default policy is DROP.
The result is
port 22 open
port 80 open
Why it is so? Pls advise. Thanks in advanced.
ben
[-- Attachment #2: Type: text/html, Size: 3117 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2002-11-05 3:37 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-11-01 10:44 does the ip_conntrack subjected to DOS attack??? Ben Tan
2002-11-05 3:37 ` Jet
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox