TCP stack errors

From: Jose Hidalgo Herrera (jose_at_hostarica.com)
Date: 01/31/05

  • Next message: Xin LI: "Re: Idea about "skeleton jail""
    To: Hackers-FreeBSD <freebsd-hackers@freebsd.org>
    Date: Mon, 31 Jan 2005 10:30:05 -0600
    
    

    I have a 4.10p5
            (cvsuped with RELENG_4_10 last friday)
    that shows things like this with a netstat -sf inet:

    tcp:
                    3630 discarded for bad checksums
                    85 discarded for bad header offset fields
            1220093 bad connection attempts
             137097 embryonic connections dropped
     udp:
            7 with bad checksum
     
    the complete netstat can be found in:
    http://www1.cr.freebsd.org/~jose/netstat-sf

    One can assume that the server is that target for some stupid guy,
    BUT the thing is that IS the server the one SENDING the miscalculated
    packages.

    I saw that with sshd connections, smtps, auths, etc.., the client sent
    the handshake but the server was replying with wrong packages.

    It occurs with different window-sizes, different flags, the network card
    is an em:
    em1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
            options=3<RXCSUM,TXCSUM>
            media: Ethernet autoselect (100baseTX <full-duplex>)
    with two ip addresses in the same subnet (alias with /32 netmask)
    no hardware failures reported.

    It sends bad packages from both addresses.

    Is there any bug I'm not aware of with this driver ?

    -- 
    Jose Hidalgo Herrera <jose@hostarica.com>
    Corp. Hostarica
    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"
    

  • Next message: Xin LI: "Re: Idea about "skeleton jail""

    Relevant Pages

    • Re: Reason of "dropped due to full socket buffers" UDP
      ... Continuous 'netstat -sp ... udp' with 100 ms. interval shows dropped UDP due to full socket ... buffers sometimes. ... The server is used as SIP server with RTP proxy. ...
      (freebsd-net)
    • Reason of "dropped due to full socket buffers" UDP
      ... Continuous 'netstat -sp ... udp' with 100 ms. interval shows dropped UDP due to full socket ... The script also monitors 'netstat -anp udp' and ... The server is used as SIP server with RTP proxy. ...
      (freebsd-net)
    • Re: Removing a DP
      ... What if I had DPs all across the US and wanted to remove ... you create another server share on ... Delete the shared folder that contains the packages manually. ... > Microsoft Online Partner Support ...
      (microsoft.public.sms.admin)
    • [FLSA-2005:166941] Updated httpd and mod_ssl packages fix two security issues
      ... The Apache HTTP Server is a popular and freely-available Web server. ... A flaw was discovered in Apache httpd where the byterange filter would ... Users of mod_ssl and Apache httpd should update to these errata packages ... where is a list of the RPMs you wish to upgrade. ...
      (Bugtraq)
    • [Full-disclosure] [FLSA-2005:166941] Updated httpd and mod_ssl packages fix two security issues
      ... The Apache HTTP Server is a popular and freely-available Web server. ... A flaw was discovered in Apache httpd where the byterange filter would ... Users of mod_ssl and Apache httpd should update to these errata packages ... where is a list of the RPMs you wish to upgrade. ...
      (Full-Disclosure)