Linux Netfilter discussions
 help / color / mirror / Atom feed
* Dropping SYN with FIN flag set
@ 2003-10-21 15:47 James Miller
  2003-10-21 16:39 ` Chris Brenton
  0 siblings, 1 reply; 8+ messages in thread
From: James Miller @ 2003-10-21 15:47 UTC (permalink / raw)
  To: netfilter

Hi folks.. sorry if this is a really dumb question.. please don't flame me
too much.

Nessus is always alerting on  "Remote host does not discard TCP SYN packets
which have the FIN flag set".  What is the best way to close up this hole?
Is there a global rule I could setup or do I need to set this on a per rule
basis?

something like '-p tcp --tcp-flags SYN,FIN -j DROP'





Thanks,
Jim




^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2003-10-21 21:35 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-21 15:47 Dropping SYN with FIN flag set James Miller
2003-10-21 16:39 ` Chris Brenton
2003-10-21 17:51   ` Jeffrey Laramie
2003-10-21 18:56     ` Chris Brenton
2003-10-21 19:29       ` Tom Marshall
2003-10-21 19:47         ` Chris Brenton
2003-10-21 20:35       ` Jeffrey Laramie
2003-10-21 21:35         ` Chris Brenton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox