[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: setting sysctl net.ipv4.ping_group_range



On Apr 12, Helmut Grohne <helmut@subdivi.de> wrote:

> As much as I like unprivileged operation, I think this change may expand
> privileges beyond what we expect. At present, ping limits an
> unprivileged user to a minimum spacing of 2ms and prevents a flood ping.
> Of course a user can just run multiple ping processes in parallel to
> overcome this limitation.
Real life DoS attacks from unpriviledged account are made with udp.pl 
and they are already quite damaging, so I do not believe that adding an
ICMP option would make the situation worse.

-- 
ciao,
Marco

Attachment: signature.asc
Description: PGP signature


Reply to: