Re: Internet SYN Flooding, spoofing attacks
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Internet SYN Flooding, spoofing attacks



> From: Valdis.Kletnieks at vt.edu

> ...
> Well.. as soon as somebody presents us with "the real solution", we'll start
> implementing.  In the meantime, filtering is the best we know how to do.
> ...

I really wish "we" actually knew how to filter.

Just as I feared when the news broke, I'm seeing more paths where neither
traceroute nor ping work, apparently because some of "us" are so expert
that we turn off all of ICMP, and never mind intermittent blackholes from
Path MTU Discovery or diagnosing routing or other mere technical problems.


Vernon Schryver    vjs at rhyolite.com




Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.