Revised draft on ICMP attacks against TCP

From: Fernando Gont (fernando_at_gont.com.ar)
Date: 10/24/05

  • Next message: David Weise: "Re: Help writing a back up script"
    Date: Mon, 24 Oct 2005 13:07:45 -0300
    To: security-basics@securityfocus.com
    
    

    Folks,

    I have published a revision of my draft on ICMP attacks against TCP. Some
    new stuff you may find interesting is a corner case for the attack against
    the PMTUD mechanism, that could allow an attacker to freeze TCP
    connections, even those secured by means of IPSec. You can find that stuff
    in Section 7.1 of the draft. This revision also addresses some recent
    discussions at the TCPM WG mailing-list.

    The draft is available at
    http://www.gont.com.ar/drafts/draft-gont-tcpm-icmp-attacks-05.txt
    (http://www.gont.com.ar/draft/icmp-attacks-against-tcp.html)

    Feedback is welcome, noise should go to /dev/null.

    --
    Fernando Gont
    e-mail: fernando@gont.com.ar || fgont@acm.org
    

  • Next message: David Weise: "Re: Help writing a back up script"

    Relevant Pages

    • [Full-disclosure] Revised draft on ICMP attacks
      ... I have published a revision of my draft on ICMP attacks against TCP. ...
      (Full-Disclosure)
    • Revised draft on ICMP attacks
      ... I have published a revision of my draft on ICMP attacks against TCP. ...
      (Bugtraq)
    • ICMP attacks against TCP
      ... I have authored an internet-draft on ICMP attacks against TCP. ... stated in the draft, ... Transmission Control Protocol (TCP) and other similar protocols. ... It proposes several counter-measures to eliminate or minimize the ...
      (comp.security.misc)
    • Re: Fortuna
      ... > The ISN selection is there only to make it harder to accomplish TCP ... > connection); and we also rekey every few minutes, ... collision attacks are not directly relevant. ... subpool 31 is added every 6.8 years. ...
      (Linux-Kernel)
    • Re: TCP RST attacks and Windows Servers
      ... Pretty much any and all system running Windows or another OS with IP v4 is ... However, most client TCP implementations, including Windows TCP networking ... Note that it is not truly trivial to do these attacks. ... an attack script to exploit this vulnerability has been out there for ...
      (microsoft.public.windows.server.networking)