Re: Evil TCPD? (Was: Re: UseNet Gateway One Way ok?)

Alan Cox (alan@lxorguk.ukuu.org.uk)
Mon, 26 May 1997 22:47:53 +0100 (BST)


> say? Well, if the kernel has the tcpd controlls or tcpd can get high enough
> in the IP stack then it can do all sorts of evil IP level tricks:

Wakey wakey ;) - man ipfwadm

> - Block the connection all together (silently drop the syn)
> (ICMP dest unreachable)

Can do those

> The connection can be dropped anywhere from verification of the helo to the
> '.' terminating the data [after hours of sending data at bytes per minute
> speeds :-)]

Sending a TCP MSS of 4 is quite funny