On Fri, Jun 20, 2008 at 12:49:43PM -0700, Darrin Chandler wrote:
It's a fair statement if by 'forced' you mean, 'compelled beyond your
control, with no other options, having fully understood the consequences
and informed all relevant parties of the risks involved'. This
"feature" is NOT a substitute for good network design.
sloppy state performs basically NO security checks on the TCP stream;
more importantly the TCP state tracking is extremely loose and it's
trivial for an attacker to spoof creation of "fully-established" TCP
connections, which will not time out for an extremely long time, filling
your state table and blocking legitimate traffic. It's dangerous.
| Trent Piepho | [PATCH] [POWERPC] Improve (in|out)_beXX() asm code |
| Andi Kleen | [PATCH] [4/50] x86: add cpu codenames for Kconfig.cpu |
| Andi Kleen | [PATCH] [0/45] x86 2.6.24 patches review I |
| Stoyan Gaydarov | From 2.4 to 2.6 to 2.7? |
git: | |
| Jarek Poplawski | Re: HTB accuracy for high speed |
| David Miller | Re: [GIT]: Networking |
| Gerrit Renker | [PATCH 13/37] dccp: Deprecate Ack Ratio sysctl |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
