Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > Phex (Cross-platform) > General Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Discussion For anything which doesn't fit somewhere else (for PHEX users)


Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old January 15th, 2008
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default Phex and Reset Packets

I would think that the software (Phex, in particular) would have to be written to look for the reset packets, or at least written to handle them differently than it does right now.

From what I've seen, the attackers are able to terminate maybe 90% of incoming packets by altering them. On a busy machine with a fat connection, that percentage would likely drop. I don't doubt that you can make Phex reject all reset packets, but that would compromise the overall TCP structure. Not a good solution, as it would introduce a high level of errors (or the potential) in the system.

Ideally, you'd want to change the software to reject BOGUS reset packets, but, as Aaron has pointed out, the bad ones look just like good ones. Perhaps it is possible instead to have Phex spend less time dealing with the reset packets, which would free up more processing time (and incoming slots) to deal with the legit requests coming through.

Something to ponder, anyway.

Cheers,

Nick
Reply With Quote
  #12 (permalink)  
Old January 17th, 2008
arne_bab's Avatar
Draketo, small dragon.
 
Join Date: May 31st, 2002
Location: Heidelberg, Germany
Posts: 1,881
arne_bab is a great assister to others; your light through the dark tunnel
Default

I forwarded your message to our lead dev (gregor_k).
__________________

-> put this banner into your own signature! <-
--
Erst im Spiel lebt der Mensch.
Nur ludantaj homoj vivas.
GnuFU.net - Gnutella For Users
Draketo.de - Shortstories, Poems, Music and strange Ideas.
Reply With Quote
  #13 (permalink)  
Old January 18th, 2008
arne_bab's Avatar
Draketo, small dragon.
 
Join Date: May 31st, 2002
Location: Heidelberg, Germany
Posts: 1,881
arne_bab is a great assister to others; your light through the dark tunnel
Default

For Phex, the TCP management is done in the OS, so we can't (easily) access it.

Are there firewalls which can be cconfigured to kill out excess RST headers easily?
__________________

-> put this banner into your own signature! <-
--
Erst im Spiel lebt der Mensch.
Nur ludantaj homoj vivas.
GnuFU.net - Gnutella For Users
Draketo.de - Shortstories, Poems, Music and strange Ideas.
Reply With Quote
  #14 (permalink)  
Old January 18th, 2008
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default Firewalls and TCP (and Phex)

I don't know of any under a Windows environment - not even with Win Server 2003. There are in Linux, though, at least in my version (RHEL - Red Hat Enterprise Linux). The Linux version of Phex runs fine under it, but I know most people are running a Win variant (as am I, on most of my systems).

I will talk to some of my guys who are more TCP/IP literate than I am, and see what they have to say. Unfortunately, if you stay in IT long enough, eventually everyone else does the work and you just sit around signing things.

By the way, Cox has ceased their attack, at least for now. They kept it up for nearly a week.

Cheers,

Nick
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:04 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.