Re: SYN flood and IP spoofing
Hello.
On lun, 12/04/00 dic 00, a las 03:09 Julien Stern wrote:
>
> ...
>
> So, my question is: what is the spoof protection doing exactly?
> Can I assume the attacks are actually coming from the IP addresses
> that are listed or is it feasible for someone to produce lines
> in my logs with any source IP address?
>
AFAIK, you can't trust source IP address of external incoming packets. Here is where ip-spoofing get in scene. You say: I don't accept packets from the outside (external interface(s)) claming to come from a internal IP.
--
He pedido drivers para Linux. Nº 00073030:
http://www.libranet.com/petition.html
José Esteban
Granada. Spain.
Reply to: