Hmmm, I was under the impression (from the CERT advisory) that a SYN
attack can go unnoticed. It WILL cause the net service that is being
provided to lock up (since all available connections are taken) but
other services will operate normally. Or am I thinking of a different
attack? This is from the CERT advisory concerning a denial of service
by filling the structure that keeps track of open connections to a
service with half-open connections (a syn but no syn-ack).
-- George Bonser -- grep@cris.com I would rather have an insincere person telling me nice things than have a sincere person telling me the truth.--Brenda (Rhoda's sister)