[AWS] Question: Can opening more than the number of allowed sessions break aws?

Pascal Obry p.obry@wanadoo.fr
Sat, 6 Jul 2002 11:13:20 +0200


Dmitriy Anisimkov writes:
 > >  > Nothing was appearing in the aws log about this activity 
 > >  > however when I look at the Admin-Page I can see the same IP at all the
 > >  > different 40 sessions.
 > > 
 > > I just don't understand how this is possible... I'm far from being a
 > > network expert...
 > 
 > I guess the intruder is connecting to the AWS,
 > but not sending the correct HTTP request.

Ok, but how an UPD connection can be accepted by an TCP/IP protocol ?
Is that possible ?

 > If so, AWS is stable for this kind of attack.
 > We have a timeout for receive correct HTTP request.
 > If client not sending correct HTTP request header in a 2-3 seconds,
 > his socket connection is closed.

Right.

Pascal.
 Just showing my ignorance about network protocols :)

-- 

--|------------------------------------------------------
--| Pascal Obry                           Team-Ada Member
--| 45, rue Gabriel Peri - 78114 Magny Les Hameaux FRANCE
--|------------------------------------------------------
--|         http://perso.wanadoo.fr/pascal.obry
--| "The best way to travel is by means of imagination"
--|
--| gpg --keyserver wwwkeys.pgp.net --recv-key C1082595