|
|
Re: [PATCH net-next] tcp: implement RFC 5961 4.2 |
From: Eric Dumazet <eric.dumazet@xxxxxxxxx> Date: Tue, 17 Jul 2012 13:41:30 +0200 > From: Eric Dumazet <edumazet@xxxxxxxxxx> > > Implement the RFC 5691 mitigation against Blind > Reset attack using SYN bit. > > Section 4.2 of RFC 5961 advises to send a Challenge ACK and drop > incoming packet, instead of resetting the session. > > Add a new SNMP counter to count number of challenge acks sent > in response to SYN packets. > (netstat -s | grep TCPSYNChallenge) > > Remove obsolete TCPAbortOnSyn, since we no longer abort a TCP session > because of a SYN flag. > > Signed-off-by: Eric Dumazet <edumazet@xxxxxxxxxx> Looks good, applied, thanks Eric. -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html
[Linux Kernel Discussion] [Ethernet Bridging] [Linux Wireless Networking] [Linux Bluetooth Networking] [Linux Networking Users] [VLAN] [Git] [IETF Annouce] [Linux Assembly] [Security] [Bugtraq] [Photo] [Singles Social Networking] [Yosemite Information] [MIPS Linux] [ARM Linux Kernel] [ARM Linux] [Linux Virtualization] [Linux Security] [Linux IDE] [Linux RAID] [Linux SCSI] [Free Dating]
![]() |
![]() |