known TCP vulnerability ??

Andy Hilker ah at crypta.net
Fri Feb 11 20:31:23 GMT 2005


Hi,

You (Li, Qing) wrote:
>
>       http://www.kb.cert.org/vuls/id/464113
>
>       http://www.linuxsecurity.com/content/view/104980/98/
>
>       Ran the packet tests against FreeBSD 5.3 and 6-CURRENT and both
>       respond to the SYN+FIN packets with SYN+ACK.


do you have 

"options         TCP_DROP_SYNFIN" 

in your kernel config?

bye,
Andy




More information about the freebsd-current mailing list