daily CVS update output

2015-01-19 Thread NetBSD source update
Updating src tree: P src/distrib/notes/common/main P src/lib/libc/stdlib/strtonum.3 P src/share/man/man4/alc.4 P src/sys/arch/amiga/dev/sbic.c P src/sys/arch/sparc64/include/mdesc.h P src/sys/arch/sparc64/sparc64/mdesc.c P src/sys/dev/pci/if_alc.c P src/sys/dev/pci/hdaudio/hdaudiodevs P src/sys/de

Re: DoS attack against TCP services

2015-01-19 Thread Michael van Elst
b...@update.uu.se (Johnny Billquist) writes: >Timeout should not depend on distance, and should actually be (at least) >2*MSS, which would be something in the several minutes range. It's 2*msl but msl can be a bit variable net.inet.tcp.mslt.enable = 1 net.inet.tcp.mslt.loopback = 2 net.inet.tcp

Re: DoS attack against TCP services

2015-01-19 Thread Johnny Billquist
On 2015-01-19 10:24, Michael van Elst wrote: 6b...@6bone.informatik.uni-leipzig.de writes: Unfortunately, all TCP connections are now in the TIME_WAIT state. bash-4.3 # netstat -a -n | grep TIME_WAIT | wc -l 34611 Is there a way to remove it without rebooting the server? tcpdrop(8)?

Re: DoS attack against TCP services

2015-01-19 Thread 6bone
On Mon, 19 Jan 2015, Michael van Elst wrote: Date: Mon, 19 Jan 2015 09:24:02 + (UTC) From: Michael van Elst To: current-users@netbsd.org Newsgroups: lists.netbsd.current-users Subject: Re: DoS attack against TCP services 6b...@6bone.informatik.uni-leipzig.de writes: Unfortunately, all TC

Re: DoS attack against TCP services

2015-01-19 Thread Michael van Elst
6b...@6bone.informatik.uni-leipzig.de writes: >>> Unfortunately, all TCP connections are now in the TIME_WAIT state. >>> >>> bash-4.3 # netstat -a -n | grep TIME_WAIT | wc -l >>> 34611 >>> >>> Is there a way to remove it without rebooting the server? >> >> tcpdrop(8)? >It works. But why does

Re: DoS attack against TCP services

2015-01-19 Thread 6bone
On Sun, 18 Jan 2015, Mindaugas Rasiukevicius wrote: Date: Sun, 18 Jan 2015 23:22:47 + From: Mindaugas Rasiukevicius To: 6b...@6bone.informatik.uni-leipzig.de Cc: current-users@netbsd.org Subject: Re: DoS attack against TCP services 6b...@6bone.informatik.uni-leipzig.de wrote: Hello, it w