On Sun, Jun 12, 2005 at 02:22:47PM +0200, Thomas Graf wrote:
quoted
Look at the first check inside th->ack in tcp_rcv_synsent_state_process.
Usually a continious flow of ACK+RST is used to prevent a connection
from being established, it's more reliable because even if you hit the
ISS+rcv_next window the connection attempt will still be reset.
Sure. My point is that there are a hundred and one ways to attack
a TCP connection in a manner similar to the original method that
started this thread. So fixes like this are pretty pointless.
Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt