frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

What's the deal with distributed SYN DOS attacks

3•xmddmx•1h ago
I run some boutique web servers (Apache on macOS, https on 443) and most of them were being weird - occasional slowdowns. Apache logs were mostly blank. CPU and RAM were close to 0% usage.

But even a curl test on localhost was showing 1,2, or more seconds longer slowdown.s

After a lot of digging, realized that I was victim of some sort of DOS attack, which appeared to be a SYN flood attack.

In a normal SYN flood attack the SYN packets are sent from one IP address then never reply, leaving the server in a state with multiple connections stuck in the "SYN_RECVD" state.

In this attack, the SYN packets are actually being "sent" from multiple IPs - and one theory is that these are forged IPs, so the attack is really a reflection attack, where the attacker sends a forged IP SYN to my server, which replies (several times with SYN ACK)

I blocked the IP block /16 at the firewall and all was well, but this made me wonder:

How are modern OS's so vulnerable to this? On my macOS server, I could run netstat -anp tcp | grep '\.443 ' and see about 128 entries stuck in "SYN_RCVD" at which point the server just went to pieces.

In other words, if my server received 128 "SYN" packets, it would die for about 75 seconds.

Is this a macOS only problem? Are other OS's susceptible to this?

for this question, please consider "Use CloudFlare" off limits. I'm more interested in why modern OSs can be so fragile to a few (forged) TCP packets.

Give Up GitHub – Software Freedom Conservancy

https://sfconservancy.org/GiveUpGitHub/
1•nreece•1m ago•0 comments

AI Project Handoff Format

https://github.com/yy4uic-ai/ai-handoff-forma
2•yy4uic•6m ago•1 comments

Commit What You Know of Iran to the Flames

https://www.bloomberg.com/opinion/articles/2026-03-06/oil-shock-commit-what-you-know-of-iran-to-t...
1•petethomas•7m ago•0 comments

Show HN: DailyDefense – Daily tower defense for agents or humans

https://www.dailydefense.ai
1•pj4533•8m ago•0 comments

OpenAI robotics lead Caitlin Kalinowski quits in response to Pentagon deal

https://techcrunch.com/2026/03/07/openai-robotics-lead-caitlin-kalinowski-quits-in-response-to-pe...
2•SilverElfin•8m ago•0 comments

MonoGame: A .NET framework for making cross-platform games

https://github.com/MonoGame/MonoGame
1•azhenley•9m ago•0 comments

A23a was once the biggest in the world iceberg. Now it has just weeks left

https://www.bbc.co.uk/news/resources/idt-20f878f1-f4af-4022-9f62-b0515b9f4b20
1•reconnecting•10m ago•0 comments

Show HN: Too many AI SaaS launching every day so we built Arena where they fight

https://glad-ia-tor.com/
1•GiornoJojo•12m ago•0 comments

Show setup modal with confetti on coverage page when no CI data exists

1•nishiohiroshi•13m ago•0 comments

XC-BASIC3 Space Invaders (Pet Programming Part 3)

https://retrogamecoders.com/xcbasic3-spaceinvaders/
1•ibobev•18m ago•0 comments

Designing a Game Board for the TMS9918A

https://bumbershootsoft.wordpress.com/2026/03/07/designing-a-game-board-for-the-tms9918a/
1•ibobev•19m ago•0 comments

More Apple II chainable hard drives?

https://www.colino.net/wordpress/archives/2026/03/07/more-apple-ii-chainable-hard-drives/
1•ibobev•19m ago•0 comments

The True Scale Multiplication Grid

https://thechalkfaceblog.wordpress.com/2017/04/29/the-true-scale-multiplication-grid/
1•tzury•20m ago•0 comments

Ask HN: How to serve inference as we do with containes with cached token

1•elesbao•21m ago•0 comments

OS-Level Age Verification

https://waspdev.com/articles/2026-03-07/my-thoughts-on-os-level-age-verification
1•senfiaj•27m ago•0 comments

Old site, new site bookmarklets

https://www.autodidacts.io/old-site-new-site-bookmarklets/
1•Curiositry•30m ago•0 comments

Agent-town – A pixel-art AI agent online collaboration platform

https://github.com/geezerrrr/agent-town
2•felixding•32m ago•0 comments

Predicting Personality from Book Preferences with User-Generated Content Labels [pdf]

https://www.cs.ubc.ca/~lsigal/Publications/tac2018annalyn.pdf
1•Curiositry•33m ago•0 comments

We Moved from AWS to Hetzner. Cut Costs 89%. Here's the Catch

https://medium.com/lets-code-future/we-moved-from-aws-to-hetzner-cut-costs-89-heres-the-catch-961...
1•doener•35m ago•0 comments

Iranian Women Graduate in Stem 3× the Rate of U.S. Women and Has 5× More PhDs

https://hrnews1.substack.com/p/iranian-women-graduate-in-stem-at
2•williesmellson•35m ago•1 comments

When Distillation Strips the Soul: Safety Comparison of a Claude-Distilled Model

https://netrork.com/blog/when-distillation-strips-the-soul/
1•jrork•39m ago•0 comments

The User Is Stochastic: Testing Agentic Systems with Simulation and Evaluation

https://www.gojiberries.io/simulating-and-evaluating-agentic-systems/
1•neehao•39m ago•0 comments

They all said Hormuz closure would be brief. What if they were wrong?

https://www.lloydslist.com/LL1156532/They-all-said-Hormuz-closure-would-be-brief-What-if-they-wer...
1•everybodyknows•39m ago•0 comments

Quint: Executable Specs for Reliable Systems

https://quint-lang.org/
1•0xcafefood•40m ago•0 comments

We built a free AI local newspaper for towns that lost theirs

https://news.minir.ai/explore?town=chesterton
1•ToukoTok•43m ago•3 comments

The HArc Stack – A Web Stack Built on Raku

https://harcstack.org
1•TheWiggles•46m ago•0 comments

Show HN: Apc-CLI – sync AI memory across Claude Code, Cursor, Copilot

https://github.com/FZ2000/apc-cli
1•FZ2000•48m ago•0 comments

Ask HN: Building on-device call screening–no cloud, just local ML. Realistic?"

1•dorjedev•49m ago•0 comments

"Warn about PyPy being unmaintained"

https://github.com/astral-sh/uv/pull/17643
2•networked•50m ago•0 comments

New Strides Made on Deceptively Simple 'Lonely Runner' Problem

https://www.quantamagazine.org/new-strides-made-on-deceptively-simple-lonely-runner-problem-20260...
1•tzury•52m ago•0 comments