Re: Attacks on IPsec

From: Gregory G Rose (ggr_at_qualcomm.com)
Date: 05/18/05


Date: 17 May 2005 22:20:05 -0700

In article <d6e6em$2d3e$3@agate.berkeley.edu>,
David Wagner <daw-usenet@taverner.cs.berkeley.edu> wrote:
>Kevin Drapel wrote:
>>One attack apply on certain configurations of IPsec with ESP in tunnel
>>mode, enabled encryption but disabled integrity check. Another also
>>applies to AH with some special settings. The attacker can retrieve
>>some plaintext data using the ICMP messages.
>>
>>http://www.uniras.gov.uk/niscc/docs/al-20050509-00386.html?lang=en
>
>Huh? I confess I don't understand this vulnerability report. I thought
>IPSec made integrity mandatory for the usual modes of operation,
>ever since Bellovin's seminal Usenix Security paper. Certainly there

Oh, yes, if you use ESP, it automatically has
integrity protection. But it's perfectly allowable
to negotiate the NULL integrity algorithm.

My point from a couple of days ago, exactly.

Greg.

-- 
Greg Rose
232B EC8F 44C6 C853 D68F  E107 E6BF CD2F 1081 A37C
Qualcomm Australia: http://www.qualcomm.com.au


Relevant Pages

  • Re: Attacks on IPsec
    ... >One attack apply on certain configurations of IPsec with ESP in tunnel ... enabled encryption but disabled integrity check. ... IPSec made integrity mandatory for the usual modes of operation, ...
    (sci.crypt)
  • Re: Possibility to cheat integrity checking?
    ... Yes integrity checking can be cheated. ... Attack the update process, that is to say when you install a new software ... For exmaple redhat ships tripwire, ... alerts via sendmail, Ibreak in and modify your sendmail, or the tripwire ...
    (Focus-IDS)
  • Re: I want to legitimise my XP
    ... posts and website that you need to attack to make your point. ... If the OP bought what the seller did not have for sale, ... Nope, my integrity is an extension of my common sense, and that says you ... At least I don't want a victim to be victimized twice over the same ...
    (microsoft.public.windowsxp.general)
  • Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast
    ... personal attack or some other random bullshit about my integrity. ... This was ment to be a thread about aviation security and ...
    (Full-Disclosure)
  • Re: Attacks on IPsec
    ... Well this just brilliant cryptography. ... designers of IPSec. ... "Why on earth did you allow integrity checks to be turned off?" ...
    (sci.crypt)