看板FB_security
标 题Re: [Full-Disclosure] IETF Draft - Fix for TCP vulnerability (fwd)
发信站NCTU CSIE FreeBSD Server (Thu Apr 22 08:09:38 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
On Thu, 22 Apr 2004, Darren Reed wrote:
> > 1. RSTs exactly at last_ack_sent (always accepted)
>
> To pursue this thought further, if a FIN has been sent or received
> (connection has migrated from ESTABLISHED to CLOSE_WAIT or something
> else) then receiving an RST at this point should be much less of a
> problem, yes ?
>
> The only drawback is I've seen sessions where there's a last ditch
> attempt to get data through even though a FIN has been received.
>
> Darren
Are you suggesting that we use the strict check during the ESTABLISHED
phase, and the window-wide check during all other phases?
Mike "Silby" Silbersack
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"