Ethereal-dev: Re: [Ethereal-dev] Detecting TCP Timestamp PAWS DoS from tracefile

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Nathan Jennings <njen@xxxxxxxxxxxx>
Date: Sat, 06 Aug 2005 13:31:59 -0400
Alok wrote:
Thanks Nathan and Guy,

What confused me (which was why i didnt lookup the wiki) was that the SYNs
always have the correct checksum.
It is not :no checksum (remember TCP cheksum is around the pseudo header +
TCP stuff and i assumed that if a problem does not come up with SYN but with
the rest of the packets it must be something else.

perhaps the OS does pass correct stuff when a SYN is initiated..

Ah, I see what you and Guy mean now. I missed the point of your question... simple SYN == no payload. :o( I hadn't considered that.

Sorry for the noise (added confusion).