RFC 3514: New Bit Defined for IPv4 Headers
RFC 3514
was just released, with a new bit definition for use in the headers of IP packets. Because there are important security implications, anyone coding internet services (on either the client or server end) should probably take a look.
Finally, the scriptkiddie bit! Now we'll be able to drop all that pesky DDoS traffic with ease!
"BSD: Free as in speech. Linux: Free as in beer. Windows 10: Free as in herpes." --Man On Pink Corner in #52607549.
The bit set to 1 indicates a pr0n site, the bit set to 0 indicates a non-pr0n site.
Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
This is such an amazingly important invention, but you are 2 hours early on the release. No one was supposed to know that.
Darn! You have already thwarted my evil plans yet again.
~ kjrose
Microsoft have released a beowulf distro.
Linus has joined redhat.
Slackware is closing down.
Linux now runs on single entangled electrons at MIT
etc etc etc
Official GOD FAQ.
Hmm, a little bit of this and a little bit of that. Sounds like an old recipe from my grandma..
I love April fool's day.
Perl programmers may want to check out their beloved cpan.org site today, too. :-)
It'll be the Router Admin Full Employment Act of 2003!
"The most sensible request of government we make is not, "Do something!" But "Quit it!"
Does the DMCA impose penalties for modifying the bit?
Since the "evil" bit *MUST* be set in attack programs, I guess that will thwart all hacker attacks!! This RFC must have been sponsored by Micro$oft... After all, Microsoft makes hackers obsolete...
So saddam is part of TCP ?
Please, please, please take this wonderful advance in technology and extend it to email. Then Spam can have a new header called "Evil: Yes". Then we can leverage the same technology to do perfect Spam filtering.
- Persnickity
Hey: it's still before midnight where I am! I'll need to take this seriously for the next couple of hours...
Call me old fashioned, but I like a dump to be as memorable as it is devastating - Bender
Benign packets have this bit set to 0; those that are used for an attack will have the bit set to 1.
Note to self: Remember to set "evil" bit to 1 when launching world domination attempt.
134340: I am not a number. I am a free planet!
If your cursor finds a menu item followed by a dash, and the double-clicking icon puts your Window in the trash, and your data is corrupted 'cause the index doesn't hash, then your situation's hopeless and your system's gonna crash!!
If the label on the cable on the table at your house says the network is connected to the button on your mouse, but your packets want to tunnel to another protocol that's repeatedly rejected by the printer down the hall, and your screen is all distorted by the side effects of gauss, so your icons in the window are as wavy as a souse; then you may as well reboot and go out with a bang, 'cuz sure as I'm a poet, the sucker's gonna hang!
When the copy of your floppy's getting sloppy in the disk, and the macro code instructions cause unnecessary risk, then you'll have to flash the memory and you'll want to RAM your ROM. Quick, turn off the computer and be sure to tell your Mom!
Blatently pinched from - Twisted Monkey Entertainment
_________________
Cheap Web Site Hosting - recommended by some worker posting on slashdot!
Unfortunately the RFC neglects to define what levels of evil the values of the 128-bit strength indicator maps to.
Therefore I, on behalf of the United Corp^H^H^H^H^H States government, submit that the top values should be reserved for the following:
2^127-n
4: Unpatriotic activity.
3: Terrorism. For up to date definition, see www.dhs.gov
2: Attempt to secure personal communication by encryption
1: Circumvention of copy protection mechanisms for purposes of piracy
0: Circumvention of copy protection mechanisms for purposes of "fair use"
Note that the last bit is reserved to indicate whether the packet originates from a foreign country.
My Sig: SEGV
The fine print: Aforementioned crimes are only illegal in Afghanistan and include, but are limited to, allowing women to walk around without being entirely concealed under a table cloth, teaching children how to read and write, and singing nursery rhymes.
Here
Also note that it's actually based on the ideas initially developed by HTCPCP protocol, which just turned 5 years.
3.243F6A8885A308D313
An attacker can take advantage of the quantum nature of reality to set this bit to an indeterminate/combined value influenced by the nature of the observer of the packet. An observer who knows the evil nature of the sender of the packet will see the "evil" bit set to one, as it should be. However, unsuspecting observers, including firewalls and potential victims, will see the bit set to zero and be fooled.
The inherent subtlety of this attack is revealed by considering what happens when a security expert attempts to analyze the attack. As soon as he recognizes the evil nature of the attacker, the packets appear to have the 'evil' bit set, and his firewalls start dropping the packets, depriving him of further packets for analysis. The attack is thus even more precisely targeted towards the naive than an attack on Microsoft IIS.
Is it time to bring out the April Fools Day Tree yet?
Should I start opening the April Fools Day gifts?
Serious question: Will this bit work over Carrier Pigeon?
And one other thought, will Windows2003Server recognize it? Oh...they'll have to release the Service Pack because anything set to 0 won't get through because of a buffer overflow extension illegal operation segfault doo-hickey.
Any other cliches missed?
I liked this bit (emphasis mine):
NGWave - Fast Sound Editor for Windows
If only it was that easy to detect evil intent in real life...
"Sally, cross your legs! His bit is set to 'evil'!"
On second thought...
"Watch your cornhole, bud."
Actually I think somebody famous* established long time ago that sex, as strange as some of its involved rituals may seem to many at times, are a better alternative to war.
.gov extension has the eBit** set.
I propose that instead anything coming from or going to a
*note: Larry Flint. Watch the movie.
**I hereforth trademark this name.
My life in the land of the rising sun.
Note to self: Remember to set "evil" bit to 1 when launching world domination attempt.
Which makes me think: Will the cable company terminate my account if I forget to set the evil bit when I am DDoSing someone, as a TOS violation?
Tequila: It's not just for breakfast anymore!
Or not a secure system. Insecure systems can choose to ignore the flag (as per RFC).
My favorite quote of the RFC is:
" This document defines the behavior of security elements for the 0x0
and 0x1 values of this bit. Behavior for other values of the bit may
be defined only by IETF consensus [RFC2434]."
LedgerSMB: Open source Accounting/ERP
First this and now I noticed the W3C added an addendum to HTTP 1.1:
10.5.4.1 503.1 Slashdotted
The server is currently unable to handle the request due to a fucking slashdotting of the server. Visit slashdot.org for potential mirrors.
I'm not being a spoilsport, but after a few years April Fools Day jokes start to seem a little formulaic and predictable.
Well, ya they are predictable, they come every April 1....:)
Perhaps if they just did a few random hoaxes a year, at different times, it would be a little more fun. As it is, its kind of like acting suprised when you get socks for christmas. And just as gratifying.
Tequila: It's not just for breakfast anymore!
Our IT group must have contributed to this RFC! Now I know exactly what to think of it...
is competition good, or is duplication of effort bad?
Enough about the evil bit, where are the "naughty bits"?
I see even classic Slashdot is now pretty much unusable on dial up anymore.
I bet we could get the US Congress to pass a law making it illegal to set this bit incorrectly.
How would one go about setting the evil flag bit when you use the avian transport layer?
Fooled you - with my stupid bit~!
have we forgotten that evil people often masquerade in sheep's clothing????
stupid!
joshua
3514 translated into l337 sp34k is ESIA... Doesn't ring a bell, but Egoistic Scriptkiddy Ignoring Annihilation seems to fit...
Please direct all bug reports to
somebody set this thing to "Evil."
Gates' Law: Every 18 months, the speed of software halves.
Ya know I was thinking about my original post, and it occured to me taht Hitchcock's "the birds" is really an archetype for evil avian transport DDoS.