[Full-Disclosure] Core Internet Vulnerable - News at 11:00

From: Crist J. Clark (cristjc_at_comcast.net)
Date: 04/20/04

  • Next message: Jeremiah Cornelius: "[Full-Disclosure] Passwords for Chocolate!"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 20 Apr 2004 10:28:16 -0700
    
    

    Does anyone know WTF they are trying to say in this AP article,
    "Core Internet Technology Is Vulnerable,"

      http://story.news.yahoo.com/news?tmpl=story&cid=562&ncid=738&e=1&u=/ap/20040420/ap_on_hi_te/internet_threat

    It sounds like they are talking about a sequence number guessing
    attack on TCP BGP sessions? Sequence number prediction isn't really
    a new attack, but the story says,

      "Experts previously maintained such attacks could take between
       four years and 142 years to succeed because they require guessing
       a rotating number from roughly 4 billion possible combinations.
       Watson said he can guess the proper number with as few as four
       attempts, which can be accomplished within seconds."

    Hmmm... Four attempts... And the story makes it sound like a
    cross-platform attack, not a bug in a particular OS's ISN generation.
    FUD or is there something here?

    -- 
    Crist J. Clark                     |     cjclark@alum.mit.edu
                                       |     cjclark@jhu.edu
    http://people.freebsd.org/~cjc/    |     cjc@freebsd.org
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Jeremiah Cornelius: "[Full-Disclosure] Passwords for Chocolate!"

    Relevant Pages

    • Re: [fw-wiz] Firewalls that generate new packets..
      ... scenario, I just hadn't considered it one way or the other. ... A good IDS will find a local MITM attack such as ... and TCP/IP Sequence Number Analysis", ... I am not assuming a blind attack. ...
      (Firewall-Wizards)
    • Re: [Full-disclosure] info on ip spoofing please
      ... in that TCP sequence attack my original point is still not clear to me. ... >>Network Security Analyst ...
      (Full-Disclosure)
    • Re: question about abuse of state tables.
      ... >> The question is about TCP connection with are already in the state table. ... In general, once a TCP ... > checked for correct TCP sequence numbers. ... > reasonably good quality - the attack has been known for a few years. ...
      (comp.security.firewalls)
    • Re: [Full-disclosure] info on ip spoofing please
      ... Markoff must have found a way to locate 2 computers conversing with each ... The attack you are referring to is known as an TCP sequence prediction ... Network Security Analyst ...
      (Full-Disclosure)
    • Re: question about abuse of state tables.
      ... > firewall as a source of vulnerability or attack by hackers. ... In general, once a TCP ... checked for correct TCP sequence numbers. ... reasonably good quality - the attack has been known for a few years. ...
      (comp.security.firewalls)