OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: New tcp stack attack

From: Fernando Gont (fernandogont.com.ar)
Date: Wed Oct 01 2008 - 10:29:19 CDT


At 11:47 a.m. 01/10/2008, Dries Schellekens wrote:

> > It seems to me the "problem" is with SYN cookies.
>
>When I read the pseudo article, I had the impression that the server
>does not have to implement SYN cookies. Their sockstress program uses
>(client) SYN cookies to estabilish a lot of TCP connections with
>minimal own resources...

Yes. This is in an unnecessarily-expensive naphta attack.

Kind regards,

--
Fernando Gont
e-mail: fernandogont.com.ar || fgontacm.org
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1