1 |
> From: Frank Gruellich [mailto:frank@××××××××××××.org] |
2 |
> * Benjamin Jury <benjamin.jury@××××.com> 8. Jan 04 |
3 |
> > If you reject the packet does it not allow you to be used |
4 |
> > for DOSing a host |
5 |
> > via a spoofed IP? |
6 |
|
7 |
> I can't see, how to DoS somebody this way. It binds on attackers side |
8 |
> as much resources as on victims one. A DDoS with many more hosts, |
9 |
> flooding rejecting filters with pakets of _one_ spoofed IP# |
10 |
> (the one of the victim) could do some damage, |
11 |
|
12 |
I apologise, I did mean a DDOS. Though as you said it would not be the |
13 |
most efficient way of performing such an attack. |
14 |
|
15 |
> but discarding pakets is much less expensive than sending answers. |
16 |
|
17 |
Although that would be a fair reason to simply drop the packets. |
18 |
|
19 |
Anyway, Ill go back to lurking. :) |
20 |
|
21 |
-- |
22 |
gentoo-security@g.o mailing list |