[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SYN flood and IP spoofing



Hello.

On lun, 12/04/00 dic 00, a las 03:09 Julien Stern wrote:
> 
> ...
> 
> So, my question is: what is the spoof protection doing exactly?
> Can I assume the attacks are actually coming from the IP addresses
> that are listed or is it feasible for someone to produce lines
> in my logs with any source IP address?
> 

AFAIK, you can't trust source IP address of external incoming packets. Here is where ip-spoofing get in scene. You say: I don't accept packets from the outside (external interface(s)) claming to come from a internal IP.

-- 
He pedido drivers para Linux. Nº 00073030:
http://www.libranet.com/petition.html

José Esteban
Granada. Spain.



Reply to: