[Full-Disclosure] IETF Draft - Fix for TCP vulnerability (fwd)
    Mike Silbersack 
    silby at silby.com
       
    Tue Apr 20 23:44:51 PDT 2004
    
    
  
On Tue, 20 Apr 2004, Don Lewis wrote:
> I am concerned that step C will not solve the compatibility problem. The
> FreeBSD host is sending a FIN to close an established connection, and
> the peer host adding the window size advertised in the FIN packet to the
> sequence number acknowledged in the FIN packet, and using the sum as the
> sequence number for the RST packet, which puts the sequence number at
> the end of the receive window.
Would it be feasible for us to create a four to five element array to
track "resettable" sequence numbers?  This could hold the sequence numbers
of the last few packets transmitted, and account for that edge case as
well.  I'm very uneasy with the IETF step C - sending more packets out
into the network sounds like a new type of amplification attack.
Mike "Silby" Silbersack
    
    
More information about the freebsd-security
mailing list