Bugtraq mailing list archives

Re: explanation and code for stream.c issues


From: charon () HADES HELL GR (Giorgos Keramidas)
Date: Sat, 22 Jan 2000 05:06:56 +0200


On Fri, Jan 21, 2000 at 01:15:27PM -0600, Tim Yardley wrote:

As was mentioned in the "advisory/explanation" on the issue, ipfw cannot
deal with the problem due to the fact that it is stateless.

The attack comes from random ip addresses, therefore throttling like that
only hurts your connection or solves nothing at all.  In other words, the
random sourcing and method of the attack, makes a non-stateless firewall
useless.

Substitute 'stateless' for 'non-stateless' above.  A stateless firewall, like
IPFW is the type of firewall that is useless.

-- Giorgos


Current thread: