From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Ben Tan" Subject: does the ip_conntrack subjected to DOS attack??? Date: Fri, 1 Nov 2002 18:44:15 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <002401c28193$9fcbbba0$1801010a@demo> Reply-To: "Ben Tan" Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0021_01C281D6.ADB80D20" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: a This is a multi-part message in MIME format. ------=_NextPart_000_0021_01C281D6.ADB80D20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable hi, it seems that once the ip_conntrack table is being filled up, the = system will crash.=20 Does it means that it is very vulnerable to DOS attack? I have performed a port scan using nmap on my box, and it is able to = scan alot of ports being opened? How come this happened? I only allow = established,related tcp packets and tcp port 22 New on INPUT to the box? = The default policy is DROP. The result is=20 port 22 open=20 port 80 open Why it is so? Pls advise. Thanks in advanced. ben =20 =20 ------=_NextPart_000_0021_01C281D6.ADB80D20 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
hi,
    it seems that once = the=20 ip_conntrack table is being filled up, the system will crash. =
 
    Does it means that = it is very=20 vulnerable to DOS attack?
 
    I have performed = a port=20 scan using nmap on my box, and it is able to scan alot of ports being = opened?=20 How come this happened? I only allow established,related tcp packets=20 and tcp port 22 New on INPUT to the box? The default policy is=20 DROP.
 
    The result is =
    port 22 open =
    port 80 = open
 
Why it is so? Pls advise. Thanks in=20 advanced.
 
ben
     
 
    =
------=_NextPart_000_0021_01C281D6.ADB80D20--