Bugtraq mailing list archives
Re: denial of service attack possible
From: fitz () wang com (Tom Fitzgerald)
Date: Fri, 27 Oct 1995 13:51:14 EDT
Last night, the machine completely stopped accepting connections on port 80 to the web server.
tcp 0 0 205.164.146.26.80 146.94.1.2.2972 SYN_RCVD tcp 0 0 205.164.146.26.80 146.94.1.2.2763 SYN_RCVD
It concerns me that one remote site can so easily completely block all incoming tcp/ip connections on a port. Is this a kernel bug, or something I can take some measure to prevent on this end?
You can crank up the second argument to listen() in httpd WAY high, which will help with this. This is not a complete fix because there's also a kernel-imposed limit on the number of half-open connections, but it will get you the ability to tolerate more half-open connections before the server stops responding. In general there's no way to defend yourself against denial-of-service attacks..... this only gives you more headroom. -- Tom Fitzgerald 1-508-967-5278 Wang Labs, Billerica MA, USA fitz () wang com
Current thread:
- Re: Sendmail 8.7, 8.7.1, (continued)
- Re: Sendmail 8.7, 8.7.1 Andrew Cameron (Oct 10)
- Netscape problems (again)... Jay 'Whip' Grizzard (Oct 10)
- s-bits disappear ? Bernd Lehle (Oct 11)
- Re: s-bits disappear ? Neil Readwin (Oct 12)
- Sun's Loadmodule Patch Neil Woods (Oct 18)
- FW: WinNews Special Issue Scott Chasin (Oct 22)
- SunOS 5.5 Beta Aleph One (Oct 24)
- denial of service attack possible Mark Thomas (Oct 26)
- Re: denial of service attack possible Darren Reed (Oct 27)
- Re: denial of service attack possible Darrell Fuhriman (Oct 27)
- Re: denial of service attack possible Tom Fitzgerald (Oct 27)
- Re: denial of service attack possible Michael R. Widner (Oct 27)
- Re: denial of service attack possible Nathan Lawson (Oct 27)