Re: packets with syn/fin vs pf_norm.c
----- Original Message -----
From: "Darren Reed" <avalon@caligula.anu.edu.au>
To: "Richard Coleman" <rcoleman@criticalmagic.com>
Cc: <freebsd-security@freebsd.org>; "Garrett Wollman"
<wollman@csail.mit.edu>; "Jesper Wallin" <jesper@www.hackunite.net>; "Darren
Reed" <avalon@caligula.anu.edu.au>; "Dag-Erling Sm鷨grav" <des@des.no>
Sent: Wednesday, July 06, 2005 11:56 AM
Subject: Re: packets with syn/fin vs pf_norm.c
> In some mail from Richard Coleman, sie said:
> > 1. I thought that T/TCP was being removed from FreeBSD (already
happened?).
> > 2. It's trivial to predict Theo's response to this.
> > 3. Since T/TCP is rare, there is little motivation to alter scrub to
> > function differently than OpenBSD with respect to these packets. If
> > someone really needs this, there are plenty of alternatives.
>
> I didn't know about (1) but I'd agree with (2) and (3).
even if T/TCP was remove, sending SYN + DATA + FIN is still legal...
fooler.
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
討論串 (同標題文章)
完整討論串 (本文為第 10 之 13 篇):