Bugtraq mailing list archives

Re: Excellent host SYN-attack fix for BSD hosts


From: vern () ee lbl gov (Vern Paxson)
Date: Mon, 14 Oct 1996 10:18:23 PDT


I don't understand why window scaling would be a problem, since the window
size isn't included in the MD5 ...

Because the window scaling option is not included in any packets other than
the initial SYN.  So if you don't remember it from when the SYN is first
seen, you have no way to recover it.  The goal is to not keep any state
around, so the scale has to be buried in the munged sequence number.

                Vern



Current thread: