Researcher's Death Hampers TCP Flaw Fix
linuxwrangler writes "Security researcher Jack Louis, who had discovered several serious security flaws in TCP software was killed in a fire on the ides of March, dealing a blow to efforts to repair the problem. Although he kept good notes and had communicated with a number of vendors, he died before fixes could be created and prior to completing research on a number of additional vulnerabilities. Much of the work has been taken over by Louis' friend and long-time colleague Robert E. Lee. The flaws have been around for a long time and would allow a low-bandwidth 'sockstress' attack to knock large machines off the net."
Or was he silenced?
---- Booth was a patriot ----
Is there anything Robert E. Lee CAN'T do?
SJW: Someone who has run out of real oppression, and has to fake it.
Much of the work has been taken over by Louis' friend and long-time colleague Robert E. Lee.
Clearly this was the result of a conspiracy by veterans of the civil war. I hope the other researchers, Grant and Lincoln, hear about this.
It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
Was it necessary to refer to his colleague as Robert E. Lee? Now we're going to get a ton of "South will rise again" jokes.
Less than a week ago is was Rick752. Now this one. Definitely reinforces the importance of collaboration, and the fragile nature of ideas.
Screw off you insensitive clod.
"linux is just DOS with a UNIX like syntax" -- Galactic Dominator (944134)
New Denial-of-Service Attack Is a Killer (01 October 2008)
... so I guess this guy passing away shouldn't make us too worried.
Suspect is a guy name Brutus, last seen wearing a plain white bedsheet.
It's not a joke when you tell someone to DIAF on the Internet. What if someone told him that before he died? Think of how guilty they'd feel now!
(-1, Raw and Uncut is the only way to read)
That was my first thought reading the summary. I mean come on:
The Ides of March
Colleague "Robert E Lee"
Low bandwidth attack that can take down large servers?
I suppose we should all beware the Ides of March. Et tu, Bruce Schneier, et tu?
Exactly what I thought when I first read this. There is just to much seemingly made up stuff in the story. He died on the ides of March, his colleague is Robert E. Lee, and even his name seems made up for some reason. I went so far as to check out his facebook memorial and this still seems off to me.
Still condolences to his family.
Idiot. The correct grammar is:
He should have beworn the Ides of March.
"Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
So a good scientist dies and all Slashdotters can do is attempt whoring out a +5 Funny with lame jokes?
:(
My high regard for the Slashdot community is obviously misguided.
It's a great loss for the research community and my condolences go to his family. And really, that's a nasty way to go...
I thought you Americans did win that one?
Well, everyone's having a good laugh at the expense of the death of this guy. May as well laugh at a picture of him.
This is my sig.
This problem was demonstrated in 2000, with the NAPTHA software and its demonstration that the problem is not academic. Yes, before NAPTHA, there was some software that could demonstrate the issue but this software had issues itself (written in perl, kept state) which limited its effectiveness. SockStress is just NAPTHA revisited.
I have a fix for this problem, but there's not enough room in the margin to describe it.
You would think someone like that would have a firewall.
Comment whoring for +1 funny mods is like pimping out your girlfriend for monopoly money.
n/t
IranAir Flight 655 never forget!
The attack is very real.
New things are always on the horizon
It's a shame he had to die that way, burning to death must be horrible. I can also understand why there's going to be such a delay in fixing the TCP/IP issue: nobody ever plans for a developer being caught in a fire. Now, if he'd only managed to get hit by a bus, everything would have been OK, because everybody plans for that.
Good, inexpensive web hosting
More likely it was Shermen
"The problem with socialism is eventually you run out of other people's money" - Thatcher.
TCP isn't a specification either. Has there ever been a clean-room implementation of Internet Protocols? I doubt a working implementation could be created based solely on RFC's.
Meh. According to the link, Sockstress is simply making lots of completed TCP connections to the target. The "sneaky trick" is apparently just doing it raw, so the client OS doesn't waste memory tracking them.
Hi, I prefer only Insightful, Informative, and Interesting comments. Could you help me in setting a filter for this comments in http://slashdot.org/my/comments
I'd like to buy homeland for our 10 million people. http://twitter.com/mahadiga
...just use connlimit. There are some slight flaws in it but there is certainly no need to allow someone to open a thousand connections.
Adult Role Playing Forum
If all else fails, immortality can always be assured by spectacular error. -- John Kenneth Galbraith
And the security fix they were working on is to replace your firewall with a Stonewall (the brand name for this device, curously enough, is Jackson).
Those who can make you believe absurdities can make you commit atrocities. - Voltaire
I don't think this is about how simple it is, but how hard it is to fix it, because that is the real problem. If people only need a simple DSL to DOS a server, this is bad news. Obviously, you can limit per IP, but DDOS also becomes much easier this way.
So that's why I think it's very real, more real than say the whole BGP-security stuff. Yes it does happen and the impact might be big, but there are some fixes. But this might be a lot harder to fix.
New things are always on the horizon
Why is it that every description of this problem that I've read so far does not present a problem.
The sockstresss.com itself provides a horrible description of it in the front page. All it appears to do is open up multiple tcp sockets.
Apparently the source IPs are not spoofed, thus the syn cookies are not at play, so how can it not hit a max connections per source IP? Any tcp service worth didley must use that in some form or the other.
If someone has some (f)actual information about this, please, provide a few links...
1 Earth is warming, 2 It's us, 3 it's royally bad, 4 we need to take action NOW