Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

SYN kesh i SYN kukiji, kako funkcionishu?

[es] :: Security :: SYN kesh i SYN kukiji, kako funkcionishu?

[ Pregleda: 2341 | Odgovora: 1 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

212.194.193.212
Diavoli GG

Član broj: 68353
Poruke: 61
..njuel-bg.customer.sbb.co.yu.



Profil

icon SYN kesh i SYN kukiji, kako funkcionishu?18.12.2005. u 16:36 - pre 223 meseci
jel moze neko da mi objasni SYN kesh i SYN kukije kako funkcionishu?


[Ovu poruku je menjao 212.194.193.212 dana 18.12.2005. u 17:38 GMT+1]
 
Odgovor na temu

IcyImpact

Član broj: 64366
Poruke: 939
*.adsl.net.t-com.hr.



Profil

icon Re: SYN kesh i SYN kukiji, kako funkcionishu?18.12.2005. u 18:24 - pre 223 meseci
SYN cookies

http://cr.yp.to/syncookies.html

Citat:
What are SYN cookies?

SYN cookies are particular choices of initial TCP sequence numbers by TCP servers. The difference between the server's initial sequence number and the client's initial sequence number is
top 5 bits: t mod 32, where t is a 32-bit time counter that increases every 64 seconds;
next 3 bits: an encoding of an MSS selected by the server in response to the client's MSS;
bottom 24 bits: a server-selected secret function of the client IP address and port number, the server IP address and port number, and t.
This choice of sequence number complies with the basic TCP requirement that sequence numbers increase slowly; the server's initial sequence number increases slightly faster than the client's initial sequence number.
A server that uses SYN cookies doesn't have to drop connections when its SYN queue fills up. Instead it sends back a SYN+ACK, exactly as if the SYN queue had been larger. (Exceptions: the server must reject TCP options such as large windows, and it must use one of the eight MSS values that it can encode.) When the server receives an ACK, it checks that the secret function works for a recent value of t, and then rebuilds the SYN queue entry from the encoded MSS.

A SYN flood is simply a series of SYN packets from forged IP addresses. The IP addresses are chosen randomly and don't provide any hint of where the attacker is. The SYN flood keeps the server's SYN queue full. Normally this would force the server to drop connections. A server that uses SYN cookies, however, will continue operating normally. The biggest effect of the SYN flood is to disable large windows.


A o SYN cacheu probaj nešto saznati sa sljedećeg linka: http://people.freebsd.org/~jlemon/papers/syncache.pdf
Knowledge is power.
 
Odgovor na temu

[es] :: Security :: SYN kesh i SYN kukiji, kako funkcionishu?

[ Pregleda: 2341 | Odgovora: 1 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.