Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Chris Brenton <cbrenton@chrisbrenton.org>
To: Atsushi Nakagawa <atnak@chejz.com>
Cc: "Dharmendra.T" <dharmu@nsecure.net>,
	Ralf Spenneberg <lists@spenneberg.org>,
	Netfilter <netfilter@lists.netfilter.org>
Subject: Re: Dropping RST of SYN
Date: Mon, 08 Sep 2003 07:29:22 -0400	[thread overview]
Message-ID: <3F5C6812.2040407@chrisbrenton.org> (raw)
In-Reply-To: 20030908204206.C148.ATNAK@chejz.com

Atsushi Nakagawa wrote:
> 
> Ralf's response was to a question regarding the removal of outgoing RST
> packets that are generated in reply to incoming SYN packets.  (These
> RSTs being the kind that causes the "Connection Refused" TCP message)

DOOOOH!

> In this case, there should be no consequences with SYN flood-type
> attacks.  The only ill-effect, AFAIK, is with abortive disconnects not
> reaching remote host (and remote host will resend obselete packets
> little more times).  --A problem enough to deter me from implmementing
> this.

Guess that's what I get for jumping in mid thread. :(

I think I'm at a loss as to why we are trying to do it this way. In 
other words, if you want to stop a scanner from getting a reply from all 
of your closed ports, would it not be easier to only let SYN packets in 
to legitimate services?

Or is this another "we're a .edu stuck in Dante's fourth circle of hell 
and are not permitted to filter out services". ;-)

C



  reply	other threads:[~2003-09-08 11:29 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-04  8:50 Dropping RST of SYN Atsushi Nakagawa
2003-09-04  9:13 ` Ralf Spenneberg
2003-09-08  5:51   ` Dharmendra.T
2003-09-08 10:02     ` Chris Brenton
2003-09-08 10:58       ` Atsushi Nakagawa
2003-09-08 11:29         ` Chris Brenton [this message]
2003-09-08 11:53         ` Stephen Satchell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3F5C6812.2040407@chrisbrenton.org \
    --to=cbrenton@chrisbrenton.org \
    --cc=atnak@chejz.com \
    --cc=dharmu@nsecure.net \
    --cc=lists@spenneberg.org \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox