diff options
author | Florian Westphal <[email protected]> | 2013-09-20 22:32:56 +0200 |
---|---|---|
committer | David S. Miller <[email protected]> | 2013-09-24 10:39:58 -0400 |
commit | 086293542b991fb88a2e41ae7b4f82ac65a20e1a (patch) | |
tree | 5f868e340b74cc03ee7f7f19fd12af0c08a422a8 /lib/cpu-notifier-error-inject.c | |
parent | 8c27bd75f04fb9cb70c69c3cfe24f4e6d8e15906 (diff) |
tcp: syncookies: reduce mss table to four values
Halve mss table size to make blind cookie guessing more difficult.
This is sad since the tables were already small, but there
is little alternative except perhaps adding more precise mss information
in the tcp timestamp. Timestamps are unfortunately not ubiquitous.
Guessing all possible cookie values still has 8-in 2**32 chance.
Reported-by: Jakob Lell <[email protected]>
Signed-off-by: Florian Westphal <[email protected]>
Signed-off-by: David S. Miller <[email protected]>
Diffstat (limited to 'lib/cpu-notifier-error-inject.c')
0 files changed, 0 insertions, 0 deletions