OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Advisory Update: ServerIron TCP/IP predictability fixed
From: H D Moore (hdmSECUREAUSTIN.COM)
Date: Tue Mar 14 2000 - 20:15:57 CST


Hi,

BeOS 4.0 also has a shoddy tcp/ip stack which increases the ISS by 1 per
connection. This may been fixed by now, I haven't tested it in over a
year.

-HD

Andrew van der Stock wrote:
> The ISS is incremented by 1 for each connection, and is thus easily
> spoofable and hijackable. The predictability exposes sideband information
> about when the switch is being used by other (possibly legitimate) users.
>
> The hosts behind the switch are NOT affected by this issue. The faked IP
> addresses offer the predictability of the hosted platform (ie Linux 2.2.14
> == good luck!, Win9x == trivial joke).