Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #265214
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Help: network abuse |
| Date | 2023-12-23 23:00 +0100 |
| Message-ID | <HOich-fFFz-1@gated-at.bofh.it> (permalink) |
| References | <HNqbT-f5lB-5@gated-at.bofh.it> <HNzId-fb2a-5@gated-at.bofh.it> <HO6ut-fySn-9@gated-at.bofh.it> <HOfo5-fE1x-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Sat, 23 Dec 2023, David Christensen wrote: > Sending a RST to a falsified IP address would make the sending host into an > attacker by proxy. Why do you suggest it? > Because the OP wants it to stop. And the OP is running a server on this port that is clearly not responding properly or we'd at least see the syn+ack. Perhaps it cannot keep up with the connections. So the op needs to tell the problem clients to stop retrying. If it's malicious traffic then there's nothing the op can do to stop it except get a new ip or get their ISP to drop it before it gets to them. The op can try icmp port unreachable too. But that tells the client there's no server, rather than there's a tcp problem. If it's not a bandwidth problem then the op should just ignore it. Nobody, but nobody is going to send traffic to some random host with a fake source ip in the hopes someone will notice and start sending RST some tine later to that address instead of continuing to drop it.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 13:20 +0100
Re: Help: network abuse Tim Woodall <debianuser@woodall.me.uk> - 2023-12-21 13:50 +0100
Re: Help: network abuse <tomas@tuxteam.de> - 2023-12-21 16:00 +0100
Re: Help: network abuse gene heskett <gheskett@shentel.net> - 2023-12-21 21:10 +0100
Re: Help: network abuse Dan Purgert <dan@djph.net> - 2023-12-21 13:50 +0100
Re: Help: network abuse Greg Wooledge <greg@wooledge.org> - 2023-12-21 14:00 +0100
Re: Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 14:20 +0100
Re: Help: network abuse Andy Smith <andy@strugglers.net> - 2023-12-21 14:50 +0100
Re: Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 16:00 +0100
Re: Help: network abuse Pocket <pocket@columbus.rr.com> - 2023-12-21 16:20 +0100
Re: Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 16:30 +0100
Re: Help: network abuse Pocket <pocket@columbus.rr.com> - 2023-12-21 16:40 +0100
Re: Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 17:00 +0100
Re: Help: network abuse Jeffrey Walton <noloader@gmail.com> - 2023-12-21 17:10 +0100
Re: Help: network abuse Pocket <pocket@columbus.rr.com> - 2023-12-21 17:50 +0100
Re: Help: network abuse Alain D D Williams <addw@phcomp.co.uk> - 2023-12-21 19:10 +0100
Re: Help: network abuse Pocket <pocket@columbus.rr.com> - 2023-12-21 19:10 +0100
Re: Help: network abuse debian-user@howorth.org.uk - 2023-12-21 19:20 +0100
Re: Help: network abuse Peter Hillier-Brook <phb@hbsys.plus.com> - 2023-12-21 19:20 +0100
Re: Help: network abuse Michel Verdier <mv524@free.fr> - 2023-12-21 15:50 +0100
Re: Help: network abuse David Christensen <dpchrist@holgerdanske.com> - 2023-12-21 23:30 +0100
Re: Help: network abuse Tim Woodall <debianuser@woodall.me.uk> - 2023-12-23 10:30 +0100
Re: Help: network abuse David Christensen <dpchrist@holgerdanske.com> - 2023-12-23 20:00 +0100
Re: Help: network abuse Tim Woodall <debianuser@woodall.me.uk> - 2023-12-23 23:00 +0100
Re: Help: network abuse Pocket <pocket@columbus.rr.com> - 2023-12-23 23:30 +0100
Re: Help: network abuse Dan Ritter <dsr@randomstring.org> - 2023-12-24 01:40 +0100
Re: Help: network abuse David Christensen <dpchrist@holgerdanske.com> - 2023-12-24 04:00 +0100
Re: Help: network abuse Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-12-24 07:20 +0100
Re: Help: network abuse David Christensen <dpchrist@holgerdanske.com> - 2023-12-24 09:20 +0100
csiph-web