Re: TCP vulnerability

From: Andre Oppermann (andre_at_freebsd.org)
Date: 04/24/04

  • Next message: Alan Evans: "Re: TCP vulnerability"
    Date: Sat, 24 Apr 2004 17:22:38 +0200
    To: Chuck Swiger <cswiger@mac.com>
    
    

    Chuck Swiger wrote:
    >
    > Alan Evans wrote:
    > > I'm sure FreeBSD is vulnerable.
    > >
    > > http://www.us-cert.gov/cas/techalerts/TA04-111A.html
    > >
    > > There's a draft that (sort of) addresses this. Should
    > > we adopt it?
    >
    > This issue is being discussed on freebsd-security now, and Mike Silbersack
    > <silby@silby.com> has some patches available for review and testing.

    There has been an additional problem in some BSD stacks with RST's
    which has been fixed in FreeBSD about six years ago. The remaining
    things which are addressed in that paper are hardening measures to
    reduce the chances of a brute force blind attack. There *no* vulner-
    ablility in the sense of "send packet x" and everything breaks.

    -- 
    Andre
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Alan Evans: "Re: TCP vulnerability"

    Relevant Pages

    • Re: TCP vulnerability
      ... > I'm sure FreeBSD is vulnerable. ... > There's a draft that (sort of) addresses this. ... > we adopt it? ...
      (freebsd-net)
    • Re: ISP Software
      ... On Fri, 25 Mar 2005, Chuck Swiger wrote: ... Is FreeBSD 5.3 stable enough to be used as an ISP Box ... "cPanel" is kinda like Webmin for users, which allows the hosting user to ... boxes to them when it comes time to rebuild them. ...
      (freebsd-isp)
    • Re: freebsd IT mailing list or newsgroup?
      ... On Saturday 15 January 2005 01:12 pm, Chuck Swiger wrote: ... > Jim Durham wrote: ... >> information regarding FreeBSD. ... a corporate environment. ...
      (freebsd-questions)
    • Re: tar vs cp
      ... On Wednesday, October 1, 2003, at 04:03 PM, Felix Deichmann wrote: ... > Chuck Swiger wrote: ... No, but not all systems have "cp -R", although FreeBSD does. ... To unsubscribe, ...
      (freebsd-questions)