Re: Treason Uncloaked!

Anthony J Placilla <[email protected]>
Newsgroups gmane.linux.redhat.release.taroon.general
Message-ID <[email protected]>

Erik wrote:
> My current Server: Redhat AS Release3  2.4.21-4.ELsmp #1 SMP Fri Oct 3
> 17:52:56 EDT 2003 i686 i686 i386 GNU/Linux
> 
> I recieve lots of message as below:
> 
> CP: Treason uncloaked! Peer 203.12.220.228:30112/80
> <http://203.12.220.228:30112/80> shrinks window 3165578735:3165581495.
> Repaired.
> TCP: Treason uncloaked! Peer 203.12.220.221:59131/80
> <http://203.12.220.221:59131/80> shrinks window 76154906:76154907. Repaired.
> TCP: Treason uncloaked! Peer 203.12.220.227:39670/443

--snippity--

Various posts I've seen seem to indicate that it's being done by the
remote peer. For example:

http://lists.debian.org/debian-isp/2002/04/msg00192.html

"So it appears that someone is running some sort of "tar-pit" system
that is designed to keep sockets in a bad state and run you out of
kernel memory."

try tuning off window scaling.

echo 0 > /proc/sys/net/ipv4/tcp_window_scaling

To see if that fixes things.

-- 
Tony Placilla, RHCT, GSEC
[email protected]


GPG-Key-ID: 1024D/C78F8B64              http://pgp.mit.edu
Key fingerprint = A8D5 7AFF CE88 4179 C792  D9A9 F197 2A15 C78F 8B64

--
Taroon-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/taroon-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.