From owner-freebsd-net@FreeBSD.ORG Thu Oct 18 06:02:16 2012 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 9227A247 for ; Thu, 18 Oct 2012 06:02:16 +0000 (UTC) (envelope-from saeedeh.motlagh@gmail.com) Received: from mail-qa0-f47.google.com (mail-qa0-f47.google.com [209.85.216.47]) by mx1.freebsd.org (Postfix) with ESMTP id C79D38FC0A for ; Thu, 18 Oct 2012 06:02:15 +0000 (UTC) Received: by mail-qa0-f47.google.com with SMTP id i29so1164408qaf.13 for ; Wed, 17 Oct 2012 23:02:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; bh=xfiqw0/qqWm0Az66P0owQNuVuKKI4ieuT6Tg70uL67c=; b=RLFTDBQrRD+HmIXqdzlK0i1JILk1wXg83uDVvpoFbqYZZCr5gxbXrTqf9WA/BV6w/I +pLt9VxG7nee7zydTxiz6xiP793ba+6Ziq9Mf0KQ3xzbIU0kwWNQlXD2jB8w+QGrG1/Y WzkNrQqixuSceAf4QYhgEYrvGRBtPCfBjGH+bXMVmSJkCZARxiBWXfLBRe5RzJ8Opnv+ r5xwE+GcyZXJMjBEtpLANI3gy4tvGjFli8Nebpe+Gz1WbzmBcz5GqJ6uzk/setAzEYuz Jy9m9oPCaXwrxxdXTUu8SYzYT9w1SkaFzZgJdKB2gnU7Wac8Z4BBrZuoI+7AVsGMcSmy QgFA== Received: by 10.229.172.10 with SMTP id j10mr9252192qcz.97.1350540135160; Wed, 17 Oct 2012 23:02:15 -0700 (PDT) MIME-Version: 1.0 Received: by 10.49.105.71 with HTTP; Wed, 17 Oct 2012 23:01:34 -0700 (PDT) In-Reply-To: References: From: saeedeh motlagh Date: Thu, 18 Oct 2012 09:31:34 +0330 Message-ID: Subject: Re: TCP_DROP_SYNFIN kernel option side effects?! To: h bagade Content-Type: text/plain; charset=UTF-8 X-Content-Filtered-By: Mailman/MimeDel 2.1.14 Cc: freebsd-net@freebsd.org X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 Oct 2012 06:02:16 -0000 i know in RFC 1644 TCP packets SYN and FIN flags are set for some testing issues but not sure if it has being used in any other issues*.** * * * * * * * On Tue, Oct 16, 2012 at 6:57 PM, h bagade wrote: > Hi all, > > I need to add this option to kernel in order to defeating Nmap > OS-Fingerprinting. My system is running as Web Server and also it is the > gateway on the network. > I want to know if setting this option has any side effects on other parts > of the system? Is there any situation that SYN and FIN bits are set both in > TCP packets? Is it a normal situation? > > Any helps or comments are really appreciated. > _______________________________________________ > freebsd-net@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-net > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" >