nanog mailing list archives

Re: Syn flooding attacks


From: Vern Paxson <vern () ee lbl gov>
Date: Mon, 20 Oct 1997 11:08:27 PDT

The router could discard the SYN, remembering it, and let pass the retry SYN
that usually occurs with valid connections and does not with invalid ones.

This is no good - all the crackers have to do is modify their programs
to send two bogus SYNs, spaced apart, instead of just one.

                Vern


Current thread: