看板FB_security
标 题Re: Fw: [bugtraq] NetBSD Security Advisory 2004-006: TCP protocol
发信站NCTU CSIE FreeBSD Server (Thu Apr 22 12:01:12 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
On Thu, Apr 22, 2004 at 01:51:12PM +0200, Frankye - ML wrote:
[...]
> Additionally, the 4.4BSD stack from which NetBSD's stack is derived, did
> not even check that a RST's sequence number was inside the window. RSTs
> anywhere to the left of the window were treated as valid.
>
> The fact that this has gone unnoticed for so long is an indication that
> there have not been a large number of RST/SYN DoS attacks ocurring in the
> wild.
Hmm, is this the same issue that we corrected in 1998? Certainly we
became aware of it because it *was* being exploited.
Cheers,
--
Jacques Vidrine /
[email protected] /
[email protected] /
[email protected]
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"