Flaw in TCP leaves entire internet vunerable to attack

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Geekbabe

Moderator Emeritus<br>Elite Member
Oct 16, 1999
32,229
2,539
126
www.theshoppinqueen.com
Can you just imagine the calls that'll be flooding AOL CS reps from frantic end users wanting to know when the web is going to be closing?:Q
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
Originally posted by: spidey07
Originally posted by: hevnsnt
All the juicy stuff Is here

so they finally put it up. I was waiting for it.


Yeah I was waiting for them to go public with it, I am a member of those "companies that got fore-warning" so I have been biting my tongue until they released it.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: hevnsnt
Originally posted by: spidey07
Originally posted by: hevnsnt
All the juicy stuff Is here

so they finally put it up. I was waiting for it.


Yeah I was waiting for them to go public with it, I am a member of those "companies that got fore-warning" so I have been biting my tongue until they released it.

we'll see. Lots of vulnerable versions. hopefully most of the tier1s are using authentication...most of them use it in their backbone/peering but few do at the access layer.
 

Platypus

Lifer
Apr 26, 2001
31,046
321
136
What the hell is this noise? The fact that they're treating guessable TCP sequence numbers as a 'new' threat is ridiculous.. this has been known for so long now..

There are techniques such as SYN cookies to prevent SYN floods, it's just that no one bothers to implement them or turn them on (ie compile into kernel).
OpenBSD has been using strong cryptographic sequence numbers for a while now.

Just funny how a concept no one has any fvcking clue about (ie MSNBC) can be blown so far out of proportion..
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
d@mnit! time to patch router...I know we shoulda gone with fatpipe :| ..... stubborn boss wouldn't listen to me :|

this is what happens when the boss knows just a little to be dangerous and his ego is so big that he wouldn't dare to admit you're right :|

I bet the gov. takes him out, send Jack from 24 ;)
 

acemcmac

Lifer
Mar 31, 2003
13,712
1
0
for those of us without cisco certs but who would be on the front line of any kind of disaster, what can we do to protect our companies and schools if there is a disaster?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: acemcmac
for those of us without cisco certs but who would be on the front line of any kind of disaster, what can we do to protect our companies and schools if there is a disaster?

upgrade your router software or use BGP authentication. that will make sure you're routes are put into your providers tables. whether your provider is protected is up to them.

at the exchange point (where your ISP connects to another ISP or tier1 isp) is where the real concern should be...hopefully authentication or fixed software is on those routers.
 

acemcmac

Lifer
Mar 31, 2003
13,712
1
0
Originally posted by: spidey07
Originally posted by: acemcmac
for those of us without cisco certs but who would be on the front line of any kind of disaster, what can we do to protect our companies and schools if there is a disaster?

upgrade your router software or use BGP authentication. that will make sure you're routes are put into your providers tables. whether your provider is protected is up to them.

at the exchange point (where your ISP connects to another ISP or tier1 isp) is where the real concern should be...hopefully authentication or fixed software is on those routers.

thanks. just got to the end of the cisco release. very helpful. will take under advisment... now to pop the hood on the gateway at work... me thinks its 8 years old no reboot?
 

BCYL

Diamond Member
Jun 7, 2000
7,803
0
71
Originally posted by: CorporateRecreation
Originally posted by: BCYL
hmm... I wonder when there will be a patch to fix this in linux...

Uh protection has been out for quite some time.

Really? Which version of the kernel was the protection added?
 

DrPizza

Administrator Elite Member Goat Whisperer
Mar 5, 2001
49,601
167
111
www.slatebrookfarm.com
Originally posted by: Geekbabe
Can you just imagine the calls that'll be flooding AOL CS reps from frantic end users wanting to know when the web is going to be closing?:Q

Help AOL out: Send out an email describing the situation (in terms an idiot can understand) and tell them you know it's true because "here's a link to real technical sites that say so. Forward this on to 10 of your friends within 2 seconds of reading this or you'll be the first person bumped off the internet until they get a new internet."
 

flexy

Diamond Member
Sep 28, 2001
8,464
155
106
OMG...i see this already as the GREAT opportunity for 'lil Billy from Redmond to come up with his own version of TCP/Internet.

The he would finally have succeeded in also owning a monopoly on the internet protocol itself, what he always wanted...

 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
Does anyone know if a support contract is required to download their IOS software now? I tried my ID that I've used for 2 years to download IOS, and it tells me I have guest access...wtf? :|

Or...are there mirrors to IOS 12.3(5c) or 12.3(6a)?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: FreshPrince
Does anyone know if a support contract is required to download their IOS software now?  I tried my ID that I've used for 2 years to download IOS, and it tells me I have guest access...wtf? :|

Or...are there mirrors to IOS 12.3(5c) or 12.3(6a)?

generally some support contract is required, or an ID.
 

skace

Lifer
Jan 23, 2001
14,488
7
81
K, You lost me in here somewhere. So I'll just sit idly by and wait for the internet to crash.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: skace
K, You lost me in here somewhere. So I'll just sit idly by and wait for the internet to crash.

the core of the net should be fine, it is the outlying access layers and hosting services that have me concerened. especially the ones run by incompetent net folks.