Re: [Patch] IPv4 TCP security impovement

Joachim Baran (jbaran@hildesheim.sgh-net.de)
Fri, 8 Jan 1999 19:56:23 +0100


On Fri, Jan 08, 1999 at 02:32:15PM -0000, Greaves Tristan TM wrote:
> As it is quite a small toggle really, it might be best to make this
> a sysctl, rather than cluttering up the Configure scripts further.
Hm, this sounds OK... I'll think about it...

> Doesn't this lead to a potential DoS ? For example, if someone ran multiple
> scans against your box with faked IPs it could fill up the log partition.
I consider this as a joke. There are plenty of other
methods to fill up a log partition. Also every good
administrator should have taken advantages to avoid
or handle this...

> It's also dubious as to whether anyone doing such a scan would be using
> their real IP address anyway.
At last one IP has to be a real one. And in fact I
think most attackers aren't very carefull or they are just
beginners. I hope a real hacker would have quite more
elegant ways to get around the bricks and stones.

Bye.

-- 
Joachim Baran                   jbaran@hildesheim.sgh-net.de
Breslauerstr.18     http://prinz.hannover.sgh-net.de/~jbaran
31171 Mahlerten                       Network Administration
Lower Saxony/Germany                         and Programming

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/