gg-(E-Mail Removed) wrote:
> Hello,
>
> Recently I noticed that in connecting to a web server on a remote
> system, the server is responding to my SYN with SYN/ACK/PSH. Netfilter
> considers this an invalid combination (which it is, sort of), so the
> packet is dropped by my firewall:
>
> 2005-04-05 11:33:19 ip_conntrack_tcp: INVALID: invalid TCP flag
> combination SRC=xxx.xxx.xxx.xxx DST=yyy.yyy.yyy.yyy LEN=44 TOS=0x00
> PREC=0x00 TTL=52 ID=62896 PROTO=TCP SPT=80 DPT=36211 SEQ=1053431614
> ACK=69666177 WINDOW=11680 RES=0x00 ACK PSH SYN URGP=0 OPT (02040578)
>
> I'm looking at ways to deal with this on my side, but I just wondered
> if other people have seen this problem? Does anyone know what operating
> system(s) respond to a SYN with SYN/ACK/PSH?
>
> It seems like it must be something really unusual or I would have seen
> this before.
>
Would you please identify the system or give an URL?
IMHO, this is proper behaviour: the segment is a relative
of the nastygram alias Christmas tree segment.
--
Tauno Voipio
tauno voipio (at) iki fi