Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Code exists to exploit TCP flaw

Michael Kanellos CNET News

Published: 23 Apr 2004 09:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malicious code has been unearthed that can exploit a widely reported flaw in a popular Net protocol and possibly disrupt data transmissions, but experts say the risk of real-world problems remains fairly low.

Security-software maker Symantec said on Thursday that it had confirmed that software now exists that can take advantage of the TCP, or Transmission Control Protocol, vulnerability and that the software has been released publicly. Symantec did not create the exploiting software, but it has confirmed it could work.

The vulnerability primarily affects routers and other devices that handle traffic on the Internet. Discovered by Paul Watson, a security specialist for industry automation company Rockwell Automation, the weakness could allow a knowledgeable attacker to shut down connections between routers -- if left unchecked.

Britain's national emergency response team, the National Infrastructure Security Co-ordination Centre, brought attention to the issue on Tuesday when it released an advisory about the issue based on Watson's research, an advisory that triggered a spate of alarmist news reports.

Watson said on Wednesday that the reports were overstated -- a fix exists and most large Internet service providers and other companies have already taken remedial actions.

"The actual threat to the Internet is really small right now," Watson said Wednesday at the CanSecWest 2004 conference in Vancouver, British Columbia. "You could have isolated attacks against small networks, but they would most likely be able to recover quickly."

Symantec agreed with his assessment.

"At this time, Symantec has seen no evidence of systems being widely impacted by this exploit," Vincent Weafer, senior director, Symantec Security Response, said in a statement. "Internet service providers are aware of the TCP flaw, and fixes have been made available for some time by multiple vendors. As a result, Symantec does not feel that this exploit will have an immediate impact on Internet activity, disrupt Internet traffic or cause system outages."

The vulnerability allows for what's known as a reset attack. Many network appliances and software programs rely on a continuous stream of data from a single source -- called a session -- and prematurely ending the session can cause a wide variety of problems for devices.

For years, these attacks were considered unlikely because they were thought to require the attacker to guess the identifier of the next data packet in a session. The odds on that are about one in 4.3 billion.

Watson discovered a method that brings the odds to closer to one success in 260,000 attempts. An attacker armed with a typical broadband connection could send all 260,000 possible attacks in less than 15 seconds. Watson said Web sites that have routers that share information on the most efficient paths through the Internet -- using the Border Gateway Protocol, or BGP -- are most vulnerable to the attacks.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
64 out of 107 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Jabra Stone Bluetooth headset

I don’t get on very well with Bluetooth headsets. But it is not a prejudice against them. I don’t get on well with those flat, saucer-like in-ear headphones either. My ears are just... More

Post a comment

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters