Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Major TCP Vulnerability Unveiled
Search Topic:
view: topics flat text 
Post a:

Comments on news posted 2004-04-20 15:03:20: Late last year, a man in Milwaukee discovered a flaw in the TCP/IP protocol that has quietly sent governments and security researchers scurrying the world over. ..

page: 1 · 2 · 3 · 4 · 5
AuthorAll Replies


TrainBuff
The New Haven Railroad
Premium
join:2003-05-01
Buffalo, NY
clubs:
Internet Shutdown

A hacker who found the flaw could effectively shutdown or cause severe interruptions to the Internet. Scary!


hack3d

@cox.net
the mother of all exploits

the title says it all. it doesnt look like a simple ms patch can fix this

B777300

join:2002-01-02
reply to TrainBuff
Re: Internet Shutdown

Indeed...

laz45

join:2002-08-01
Orlando, FL
clubs:
How can this be done, i wanna do it

tdkyo

join:2002-12-07
Rochester, NY
reply to TrainBuff
Lets see if your router manufacturers can come up with a patch soon....


lua6
Premium
join:2002-08-15
New York, NY
reply to laz45
You download Hacker.exe and your on your merry way... Spare me please

Daemon
Premium
join:2003-06-29
San Francisco, CA
reply to laz45
while i'm sure you're kidding, if you have to ask, you aren't talented enough to do it.
--
-Ryan
Find me in the networking and Microsoft help forums


MightWolf

join:2002-06-17
Windsor, ON
reply to laz45
Actually, reading the details, it will be practically impossible to "shutdown the internet" - the attacker would need to know both end-points of all TCP connections.....


tomkb
Premium
join:2000-11-15
Avon, OH
clubs:
·RoadRunner Cable


1 edit
reply to laz45
said by laz45 See Profile:
How can this be done, i wanna do it

You have to hold the 'g' key down on your keyboard while booting up. Once you get to the login screen, release the 'g' key, login, and hold the down the 'g' key again until the icons appear on the left side of your screen.

This will effectively shut your portion of the internet down (maybe your whole city block). But you have to have a broadband connection and not dialup because you won't be connected to the internet at first.


bky
moof moof
Premium
join:2002-07-05
Austin, TX
reply to tdkyo
I think the article is referring to bigger routers like cisco


gruggni
Oxygen Gets You High

join:2003-07-28
Corpus Christi, TX

1 edit
Take down the internet

I'm tired of spam and viruses, just kill it already.

Stop those bastards from making money.
People will have to go outside or watch tv.

Use the phone, HAHA voip, suckers.

How much do you depend on tcp/ip?


MightWolf

join:2002-06-17
Windsor, ON
reply to bky
Re: Internet Shutdown

Well it's not like a hacker will spend hours tracking a home user's TCP inbound and outbound connections just so he can shut them down.


fatmanskinny
Premium
join:2004-01-04
Wandering
Ouch!

Maybe I will get some work out of this. Last time, I got a 2 month computer support contract because of SoBig. No telling how long my contract will be if the WHOLE INTERNET can be shut down and needs patching.


brandon
Some truth included in this post.
Premium
join:2003-03-31
Hurley, MS
Dang.

The internet's broken.


Anon-E-Mus

@rockwellautomation.c

 Way to go, Tony!!!

Tony had discovered this vulnerability about a year ago. Luckily it was first discovered by an intelligent and ethical IT security guy and not some unscrupulous hacker. He has quietly worked with vendors during that time helping them come up with a solution.


Wills

join:2001-01-03
Port Charlotte, FL

reply to gruggni
Re: Take down the internet

Think of the implicatoins of people actually having to go outside while sitting around drinking Mt. Dew and eating Twinkies for the last 4 years while playing Everquest.

Spontaneous human combustion. Sharp rise in sunburn. Possible blindness.

Heck all the spammers will just switch to selling sunglasses, tanning oil, and fire extinguishers.
--
Abit VP-6 twin 800EB's @ 1002 Mhz.Proud member of the XDC.


AthlGrond
Premium,MVM
join:2002-04-25
Aurora, CO
Well There Goes Comcast

The center "encourages all BGP enabled Juniper or Cisco router administrators to turn on MD5 checksums as soon as possible while testing the patch supplied by router vendors."

How fast do you think Comcast will do this?


Yoda2009

join:2003-10-07
Toronto, ON
No threat?

Something tells me hackers wouldn't want to take down the internet, as that's what they use. Then again if they're stupid enough...


HardwareLust
Subaru WRX Maniac
Premium
join:2002-01-02
Harrisburg, PA
clubs:

reply to MightWolf
Re: Internet Shutdown

said by MightWolf See Profile:
Well it's not like a hacker will spend hours tracking a home user's TCP inbound and outbound connections just so he can shut them down.

Depends on how bad you wanna mess with the guy at the other end. There's several people I would love to do this to, but I'm way too lazy.
--
Where the hell are my stars that I worked so hard for???


sporkme
drop the crantini and move it, sister
Premium,MVM
join:2000-07-01
Morristown, NJ
·Optimum Online

Router people, how to fix

Just got off the phone with one of our upstreams, and it was quite easy to setup. In your bgp config:


neighbor x.x.x.x password 0 somethingsecret


On hitting enter, the bgp session will reset and your router is safe from the attack.

This site has some good general suggestions for using bgp securely:

»www.cymru.com/Documents/secure-b···ate.html

FWIW, the guy I spoke with who was setting up the other end said that this is all they've been doing for the past few days.
--
Thanks for the memories
Forums » Major TCP Vulnerability Unveiledpage: 1 · 2 · 3 · 4 · 5


Monday, 14-Dec 16:07:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF