Re: SYN_RCVD

2016-06-07 Thread Peter J. Philipp
On 06/07/16 15:33, Claudio Jeker wrote: > On Tue, Jun 07, 2016 at 09:35:39AM +0200, Peter J. Philipp wrote: >> On 06/06/16 21:57, Claudio Jeker wrote: >>> OpenBSD uses the syncache for TCP sockets in the 3 way handshake to save a >>> lot of work to create a full socket in case of synfloods, etc. >>

Re: SYN_RCVD

2016-06-07 Thread Claudio Jeker
On Tue, Jun 07, 2016 at 09:35:39AM +0200, Peter J. Philipp wrote: > On 06/06/16 21:57, Claudio Jeker wrote: > > OpenBSD uses the syncache for TCP sockets in the 3 way handshake to save a > > lot of work to create a full socket in case of synfloods, etc. > > These unhatched sockets do not show up in

Re: SYN_RCVD

2016-06-07 Thread lists
> >> OpenBSD uses the syncache for TCP sockets in the 3 way handshake to save a > >> lot of work to create a full socket in case of synfloods, etc. > >> These unhatched sockets do not show up in the netstat output. Maybe they > >> should be added but this is the first request that asks for them in

Re: SYN_RCVD

2016-06-07 Thread Kapetanakis Giannis
On 07/06/16 10:35, Peter J. Philipp wrote: On 06/06/16 21:57, Claudio Jeker wrote: OpenBSD uses the syncache for TCP sockets in the 3 way handshake to save a lot of work to create a full socket in case of synfloods, etc. These unhatched sockets do not show up in the netstat output. Maybe they sh

Re: SYN_RCVD

2016-06-07 Thread Raul Miller
On Tue, Jun 7, 2016 at 3:35 AM, Peter J. Philipp wrote: > Thanks for the history of this Claudio. I am not really asking for them > I just wanted to know where they went. It's good to know that a > LISTENING tcp socket goes directly to ESTABLISHED in OpenBSD. I would > have another question tho

Re: SYN_RCVD

2016-06-07 Thread Peter J. Philipp
On 06/06/16 21:57, Claudio Jeker wrote: > OpenBSD uses the syncache for TCP sockets in the 3 way handshake to save a > lot of work to create a full socket in case of synfloods, etc. > These unhatched sockets do not show up in the netstat output. Maybe they > should be added but this is the first re

Re: SYN_RCVD

2016-06-06 Thread Claudio Jeker
On Sat, Jun 04, 2016 at 12:35:58AM +0200, Peter J. Philipp wrote: > Hi, > > In Mac OS X when I spoof a packet to it it prints somethign like this in > the netstat -na: > > - > Active Internet connections (including servers) > Proto Recv-Q Send-Q Local Address Foreign Address