Re: New tcp stack attack

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Fernando Gont <fernando@...>, <misc@...>
Date: Wednesday, October 1, 2008 - 2:11 pm

Fernando Gont wrote:

I looked this up on google, the URL for this attack is here:
http://shlang.com/netkill/ , I noticed it was a little bit
different from what I described because the state is in the FIN_WAIT_1
state on the remote machine, the TCP state
diagram in RFC 793 page 23 shows that a FIN is sent from the client's
close() to the server to reach that state, so it differs. If you have
a userland TCP/IP stack you can cease communication without the FIN
being sent.

I listened to the interview's first 5 minutes again and they mention
their own TCP/IP stack and that it was quite fast giving them a large
window; so large window, established state and userland TCP/IP stack is
their formula.

Here is the URL for the interview again the first 5 minutes are in
swedish so one can skip them:

mplayer -ss 5:0 http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3

If the discoverers of this bug don't make their sockstress available to
OpenBSD then I have a userland TCP/IP stack for OpenBSD developers (mail
me), but it's only written to be a server, but I suspect it would be
easy to make it a client, just have to dust it off from my CVS as it's
quite old (2004 possibly).

Regards,

-p

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
New tcp stack attack, Leon Dippenaar, (Wed Oct 1, 8:52 am)
Re: New tcp stack attack, Jussi Peltola, (Wed Oct 1, 11:56 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 10:13 am)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 11:24 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 11:41 am)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 12:26 pm)
Re: New tcp stack attack, Peter J. Philipp, (Wed Oct 1, 12:56 pm)
Re: New tcp stack attack, Sunnz, (Fri Oct 3, 12:18 pm)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 1:31 pm)
Re: New tcp stack attack, Peter J. Philipp, (Wed Oct 1, 2:11 pm)
Re: New tcp stack attack, Brian Keefer, (Wed Oct 1, 10:37 pm)
Re: New tcp stack attack, Stephan A. Rickauer, (Wed Oct 1, 9:31 am)
Re: New tcp stack attack, Claudio Jeker, (Wed Oct 1, 9:58 am)
Re: New tcp stack attack, Paul de Weerd, (Wed Oct 1, 10:46 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 10:22 am)
Re: New tcp stack attack, Dries Schellekens, (Wed Oct 1, 10:47 am)
Re: New tcp stack attack, Dries Schellekens, (Wed Oct 8, 7:12 am)
Re: New tcp stack attack, Alexander Sabourenkov, (Wed Oct 1, 10:44 am)