Re: Hostile webserver attack!!!!

John D. Pritchard (jdp@cs.columbia.edu)
Sat, 28 Dec 1996 14:45:24 -0500


> 
> It seems that two Hackers magazines have published the source code and
> now any webserver in the world is opened to such and attack."
> 
> (Summarised from "Globes"  http://www.globes.co.il Israel financial
> magazine, Hi-Tech section, tuesday edition).
> 
> Is any of you guys familiar with this "SYN-flood" bombimg method?  does
> anyone know how you can located this suspects and place them under a
> "black list" of forbidden sites?

goto cert

the attack fills up the response queue.  if your response queue is larger
than the flood, eg, Solaris, then there's no real vulnerability