Re: TCP Sack processing

From: Joachim Schipper (j.schipper_at_math.uu.nl)
Date: 08/11/05

  • Next message: Sanjay Rawat: "Re: Looking for HIDS-only products for XP/2000Pro"
    Date: Thu, 11 Aug 2005 10:34:43 +0200
    To: focus-ids@securityfocus.com
    
    

    On Tue, Aug 09, 2005 at 04:28:10PM -0400, snort user wrote:
    > Greetings.
    >
    > Does TCP stream reassembly algorithm need TCP SACK processing for completeness ?
    > Are there scenarios that an IDS/IPS would miss an attack if it does
    > not take the selective acks into consideration.
    >
    > Any comments/opinions/pointers is appreciated.
    >
    > Thanks

    Well, I am not an expert, but...

    Suppose I have an exploit that requires a TCP connection. I open the
    connection, send packet #1 and #3, and then sent #2 after #3 has been
    SACK'ed. Wouldn't that work, and bypass your IDS, especially if the
    exploit is divided over the packets in a smart way?

                    Joachim

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Sanjay Rawat: "Re: Looking for HIDS-only products for XP/2000Pro"

    Relevant Pages

    • Re: Why bandwidth consuming ddos attack using only udp or icmp?
      ... I know already the difference of tcp and other stateless protocol. ... I presume you are asking 'whether a TCP-based bandwidth ... the only traffic that your attack is is going to consume is the ... Why bandwidth consuming ddos attack using only udp or icmp? ...
      (Security-Basics)
    • RE: Why bandwidth consuming ddos attack using only udp or icmp?
      ... There is a limit on the size of each TCP packet. ... You would not consider sending 4.5 MB to a server a bandwidth attack. ... Why bandwidth consuming ddos attack using only udp or icmp? ...
      (Security-Basics)
    • Re: [Full-Disclosure] Bypassing "smart" IDSes with misdirected frames?
      ... > If the attacker is on the same LAN as your IDS, ... > more severe than the attack you have described. ... In a TCP handshake, usually there are TWO parties involved... ... an extra attack step involves host A sending an IP packet addressed ...
      (Full-Disclosure)
    • Re: Why bandwidth consuming ddos attack using only udp or icmp?
      ... UDP data sizes can be much larger than tcp. ... its use for packet management of existing streams. ... You would not consider sending 4.5 MB to a server a bandwidth attack. ... Why bandwidth consuming ddos attack using only udp or icmp? ...
      (Security-Basics)
    • Re: Denial of Service: Commercial Defense products
      ... Some of these fields will have to be at least bounded inside certain intervals - otherwise the attack will not be really effective or will not reach its victim. ... there is no 100% bullet proof solution against DDoS attacks. ... TCP sequence number. ... TCP checksum. ...
      (Focus-IDS)