Reflection Scan: an Off-Path Attack on TCP
- From: Jan Wrobel <wrr@xxxxxxxxxxxx>
- Date: Tue, 17 Jan 2012 23:45:25 +0100
This TCP session hijacking technique might be of interest to some of you.
The paper demonstrates how traffic load of a shared packet queue can
be exploited as a side channel through which protected information
leaks to an off-path attacker. The attacker sends to a victim a
sequence of identical spoofed segments. The victim responds to each
segment in the sequence (the sequence is reflected by the victim) if
the segments satisfy a certain condition tested by the attacker. The
responses do not reach the attacker directly, but induce extra load on
a routing queue shared between the victim and the attacker. Increased
processing time of packets traversing the queue reveal that the tested
condition was true. The paper concentrates on the TCP, but the
approach is generic and can be effective against other protocols that
allow to construct requests which are conditionally answered by the
victim. A proof of concept was created to asses applicability of the
method in real-life scenarios.
The paper in ps and pdf is available at http://mixedbit.org and
Proof of concept: https://github.com/wrr/reflection_scan
- Prev by Date: Re: pwgen: non-uniform distribution of passwords
- Next by Date: XSS in OneOrZero AIMS
- Previous by thread: ESA-2012-003: EMC SourceOne Web Search Sensitive Information Disclosure Vulnerability.
- Next by thread: XSS in OneOrZero AIMS