I have recently started receiving TCP Treason Uncloaked messages in my
daily logwatch reports from my vps on Urquell. They appear to be linked to
port 80.
OK, I understand what the message is about, the other host has suddenly
decided to reduce the size of the window during a transaction. Googling
for reasons and causes suggests it is something between and out and out
attack, a kernel or apache bug, a hiccup in TCP and is therefore extremely
serious/nothing to worry about and that I should ignore it/upgrade all
software/run round pulling out all my hair.
I am running the latest version of everything (that is available from the
lenny repository).
The httpd section of the logwatch report tells me that there have been a
number of attempts to use a known hack and it responded with a 501, but
they were reported with an ipv4 address and the treason reports had an
address that appeared to be ipv6 (though attempts to trace it failed)
There aren't many incidents in a day, but I wondered what advice/comments
users here might be able to give and, showing my ignorance here, could
this be related in some way - I've no idea how - to the recent urquell
problems?
Keith
--
Keith Williams
Solo bike ride, John O'Groats to Land's End starting 29 August 2010, in
aid of Willen Hospice. Please make a donation at
http://justgiving.com/SimonsTrip