Re: New tcp stack attack

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Peter J. Philipp <pjp@...>
Cc: Fernando Gont <fernando@...>, <misc@...>
Date: Friday, October 3, 2008 - 12:18 pm

2008/10/2 Peter J. Philipp :

I have just listened to the interview as well.

They said that they have looked at the source tree of Linux, at their
Timer code in the TCP stack. The Linux source code indeed have a
comment saying there are states that are bad and the Linux kernel
would try to avoid. So the sockstress program was written to work the
other way around, to try to get into that bad state as much as
possible, and it managed to bring down Linux systems.

They then run the same attack against a Windows machine, and it had
the same effect as well, so it really seem like a problem in the TCP
protocol.

In the article it is said that BSD are vulnerable as well, they didn't
mention if it was Free or Net or Open...

So I guess the question is if OpenBSD have such state in its TCP
stack, maybe a code auditing session (whenever it is done next, the
next Hackathon?) can look at something like that in the OpenBSD
kernel... or maybe the dev already saw this kind of problem and have
harden the TCP stack for OpenBSD?

--
This e-mail may be confidential. You may not copy, forward or use any
part. All disclaimers on the Internet are of zero legal effectiveness.
http://www.goldmark.org/jeff/stupid-disclaimers/

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
New tcp stack attack, Leon Dippenaar, (Wed Oct 1, 8:52 am)
Re: New tcp stack attack, Jussi Peltola, (Wed Oct 1, 11:56 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 10:13 am)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 11:24 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 11:41 am)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 12:26 pm)
Re: New tcp stack attack, Peter J. Philipp, (Wed Oct 1, 12:56 pm)
Re: New tcp stack attack, Sunnz, (Fri Oct 3, 12:18 pm)
Re: New tcp stack attack, Fernando Gont, (Wed Oct 1, 1:31 pm)
Re: New tcp stack attack, Peter J. Philipp, (Wed Oct 1, 2:11 pm)
Re: New tcp stack attack, Brian Keefer, (Wed Oct 1, 10:37 pm)
Re: New tcp stack attack, Stephan A. Rickauer, (Wed Oct 1, 9:31 am)
Re: New tcp stack attack, Claudio Jeker, (Wed Oct 1, 9:58 am)
Re: New tcp stack attack, Paul de Weerd, (Wed Oct 1, 10:46 am)
Re: New tcp stack attack, Duncan Patton a Campbell, (Wed Oct 1, 10:22 am)
Re: New tcp stack attack, Dries Schellekens, (Wed Oct 1, 10:47 am)
Re: New tcp stack attack, Dries Schellekens, (Wed Oct 8, 7:12 am)
Re: New tcp stack attack, Alexander Sabourenkov, (Wed Oct 1, 10:44 am)