看板FB_security
標 題Re: SYN attacks (correction)
發信站NCTU CSIE FreeBSD Server (Tue Apr 6 23:25:57 2004)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
Mark Picone wrote:
> you should add
> net.inet.tcp.drop_synfin=1 to /etc/sysctl.conf so it gets piped into sysctl
> on boot
> or just run sysctl net.inet.tcp.drop_synfin=1 as root
Unlikely the attacks will have both the SYN and FIN flags set.
Perhaps verifying net.inet.tcp.syncookies is set to 1 and use
ipfw+dummynet to rate limit incoming SYN packets.
>
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Mark Picone
> Sent: Wednesday, 7 April 2004 10:57 am
> To: [email protected]
> Subject: RE: SYN attacks
>
> You could try adding this to /etc/sysctl.conf
>
> sysctl net.inet.tcp.drop_synfin=1
>
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Spades
> Sent: Wednesday, 7 April 2004 3:02 am
> To: [email protected]
> Cc: [email protected]
> Subject: SYN attacks
>
> Heya,
>
> FREEBSD 4.9-STABLE
>
> Is there anyway to block SYN attacks and prevent it from bring down my
> server?
>
> Its been attacking for sometime.
> _______________________________________________
> [email protected] mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "[email protected]"
>
> _______________________________________________
> [email protected] mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "[email protected]"
>
> _______________________________________________
> [email protected] mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "[email protected]"
>
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"