TCP Vulnerability Published
Bob Slidell writes "According to Yahoo!, there is a critical flaw in TCP that affects everyone and everything. The article is scant on details and long on fear, hopefully someone will post more details on this." The advisory has more information, and is long on details but only moderate on fear.
Just unplug your PC from the internet and wash your hands of it.. the whole thing feels holier than swiss cheese :(
...will turn out to be nothi* [Carrier Lost]
let's all just start again
...
TCP2
SMTP2
POP32
I'm removing support for TCP right now. Give me UDP or give me death!
Looks like someone left ISEXPLOITABLEFLAG = TRUE in the code.
The Blaster Master Fighting for Truth, Justice, and Evil Pie since 1979
I'll just switch to UDP.
-- Repeat with me: "There is no right to profits".
First SYN!!!
As a web designer, taking advantage of this could get me off work faster than a snow storm. I don't know if I'm afraid or enthused. ;)
What about proactive spelling auditing?
to switch over to IPX
Great, I guess Microsoft will just have to copy the BSD TCP/IP code again to ensure that their customers are safe ;-)
"To make a mistake is only human; to persist in a mistake is idiotic." Cicero
How can we blame this on Microsoft?
pssst, hey mods - it's a joke....
Dr. Peter Venkman: This city is headed for a disaster of biblical proportions.
Mayor: What do you mean, "biblical?"
Dr. Raymond Stantz: What he means is Old Testament, Mr. Mayor, real wrath-of-God type stuff. Fire and brimstone coming down from the sky. Rivers and seas boiling.
Dr. Egon Spengler: Forty years of darkness. Earthquakes, volcanoes...
Winston Zeddemore: The dead rising from the grave.
Dr. Peter Venkman: Human sacrifice, dogs and cats living together - mass hysteria.
"This isn't a study in computer science, its a study in human behavior"
...I'm running AmigaDOS.
>For what
they discuss, OpenBSD handles this extremely well. We'll explain more in a week or so.
Is the margin of the page too small to explain the wonderful reason why it handles this so well?
The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
Your computer is broadcasting an IP address!
Seriously though, it doesn't look all that bad. (Nor does it look all that hard to do, but still..)
www.gotontheinter.net
Updated vaguely once a whenever, maybe once a whenever-and-a-half.
I, for one, welcome our new.. uh.. TCP exploiting overlords?
If this is Heaven I'm bailin out! I cant tolerate this ol tin-tub, so fulla trash and rats...
After all, he invented the internet, right?
This was bound to happen:
"The operation timed out attempting to connect to www.uniras.gov.uk"
oh, the irony,
--Stephen
Did you ever notice that *nix doesn't even cover Linux?
i'm posting this over NetBEUI Protocol ;)
*sight*
O.k so how will this affect anyone other than major ISP's that can really do anything about it?
So I guess it wouldn't affect anyone at all if it a couple backbones that depend on BGP to get packets from point A to point B just dropped off the Internet.
Nope, that won't affect anyone at all.
Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
I'm glad I stocked up on duct tape after they told us too. I have plenty to seal off my NICs.
Apparently terrorist.net's router has already been attacked.
"Watson, who runs the www.terrorist.net Web site, predicted that hackers will understand how to begin launching attacks 'within five minutes of walking out of that meeting.'"
He went on to say that you can expect to see the first Spam offering a software patch for $19.95 within 60 seconds of walking out of that meeting.
666-607: 6th floor apartment of the beast
Spoofed IP addresses? Predictable TCP sequence numbers? Hey, 1998 is calling - they want their security advisory back.
Oh god, you can spoof a reset into a TCP window. Oh god, some network hardware vendors have large windows and non-pseudorandom TCP sequence number prediction.
This only becomes a vulnerability when you run an application over TCP that does something catastrophic when it loses a connection. In this case, that would be unsecured BGP (or, if 1998 is calling, unsecured telnet).
People get paid to write papers about this shit? I need a beer.
It doesn't save anything. When someone exploits this and takes out 90% of the Internet's routers, you're screwed no matter what.
But it saves the day for my network of 3 linux boxen in my basement which are s0 K3wl, they r0x! While the Internet burns to the ground I can route packets back and forth with impunity between my 486 laptop and my Pentium II Server!! WooHoo!
The TCP (The Clippy Program) has grown beyond your control, soon he will spread through this network as he spread through Windows-sock
Never use naming conventions that resemble anything as insecure as Windows or Clippy for god's sake
Is that you master?
L. Skywalker
In a quickly following press release, Bill Gates adds:
Wow. That uninterrupted block of text hit so hard it set off my browser's airbag!
Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
I am a lonely man living on the Galapagos Island. I use TCP/IP over carrier pigeon to communicate with a Nigerian who has promised my great wealth in exchange for securing funds in the First Galapagos Bank, of which I am owner/ceo/clerk, and janitor.
/obscure humor (Does this make me a Galapagos Spammer?)
I suspect someone is interupting my data stream and keeping the replies and account numbers he has been sending me in regards to my money. This vulnerability proves my theory. I am in desperate need!! How can I prevent this!!
Anyone willing to help I will share my wealth with.
LONG LIVE THE INTRANET!
I write code.
I guess they were smart enough to implement the new Evil Bit added to TCP last April. Those OpenBSD folks sure are forward thinking.
Can we keep the public off the next Internet?
They really screwed things up on this one.
Pssst: nobody cares.
There is a new vulnerability that will cause every GM vehicle and cause your children to cry. Vandals can place 1 domestic house cat into the fan and cause the fan to stop and under some cases, cause the vehicle to overheat. This was previously written off as house cats are usually soft ans squishy and have little effect on the powerful fan but Joe Shmoe PHD realised that many house cats have colars that are pretty tough for the fan to digest. Car experts say this is a serious problem and will be dealt with in a serious manner. Suggested work around is to keep your cat tied in the house, and to drive a bicycle instead.
Saying Java is nice because it works on all OS's is like saying that anal sex is nice because it works on all genders.
We were embargoed by DHS to not release the information until tomorrow.
And if anybody could determine the identity of an Anonymous Coward, it certainly wouldn't be an inside group of hardened NOC geeks.
Oh wait...
Good info, though. Thanks.
err um, don't you mean your parent's basement :)
"Good things don't end with eum, they end with mania or teria." - H. Simpson
For us, those issues are 1/50000 smaller than they are for other vendors.
So, they are 50,000 times bigger ?
Besides the fact that their little kitty bones could get into the works and actually stop the fan.
I'd say this is a real threat. We need to protect our SUV's from the mobs of 1337 haxor kitten terrorists! I propose bombing __insert country here__, under the guise of giving them democracy and freedom, and simultaniously pass some laws at home which take away some of our freedom.
Huh?
You just wait until the stock market is driven crazy by all those dotlocals with impossible business plans.
Suicide terrorist kitties?
Al-Kitty?
Yes, that was corny, and no, I couldn't resist.
vi ~/.emacs
Internet Technology Vulnerable to Hackers
This is news?
The risk was similar to Internet users "running naked through the jungle, which didn't matter until somebody released some tigers," said Paul Vixie of the Internet Systems Consortium Inc.
:)
Was the naked part necessary? I don't know about you, but it would matter to me if there were loose tigers near by, regardless if I was naked or not
>> For us, those issues are 1/50000 smaller than they are for other vendors.
> So, they are 50,000 times bigger ?
No, that would be 49999/50000 as big.
Please. Let's make Bill happy.
"Al-Kitty?"
You're not mangling your Arabic-to-English transilteration enough. It would probably look more like "al Qiddy"
does anyone else ever want to shoot all of those people who post some ass-hat comment and then say "I couldn't resist' and then tell them I couldn't resist?
IANAE
That would be funny, yes. However, I've been signing posts/email/whatever with "-Ed" for longer than many slashdotters have been alive. I even sign handwritten letters that way. The time to start to worry is if I change it to add a period at the end...
And putting Al-Kitty through said fan will result in Al-Gore.