>Number:         190102
>Category:       misc
>Synopsis:       net.inet.tcp.drop_synfin=1 no longer works on FreeBSD 10+
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    freebsd-bugs
>State:          open
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Thu May 22 11:50:01 UTC 2014
>Originator:     Mark Felder
>Release:        10.0-RELEASE
SupraNet Communications Inc.
FreeBSD wil.supranet.net 10.0-RELEASE-p3 FreeBSD 10.0-RELEASE-p3 #0: Tue May 13 
18:31:10 UTC 2014     
r...@amd64-builder.daemonology.net:/usr/obj/usr/src/sys/GENERIC  amd64

net.inet.tcp.drop_synfin=1 no longer works on FreeBSD 10+

Run this scan on identically configured FreeBSD 9 and FreeBSD 10 servers

nmap -v -v --scanflags SYNFIN -P0 <target>

FreeBSD 9 servers will report "filtered" which is correct. FreeBSD 10 servers 
will report "open", which means it is vulnerable to this attack to bypass the 

The firewall in use on these machines is pf. It is possible to block SYN/FIN on 
pf as well, but our standard deployment is the sysctl method.

freebsd-bugs@freebsd.org mailing list
To unsubscribe, send any mail to "freebsd-bugs-unsubscr...@freebsd.org"

Reply via email to