Posted on Wednesday, October 1st, 2008 | Bookmark on del.icio.us

Thoughts on the TCP/IP Stack DoS

by Jose Nazario

Speculation is rampant after reports of a new TCP stack denial of service attack have been announced. The attack details have yet to be make public – it’s for a talk at this year’s T2 event in Finland – but folks are anxiously looking for details.

We don’t have any.

Probably the most detail I’ve seen publicly shared is this detailed blog post from belsec. So far this sounds like a minor variant on known attack vectors, ie Naptha, or other state holding attacks.

The folks behind Unicorn scan are no slackers and know TCP/IP stack internals better than almost anyone, so I anticipate that it’s really a new attack, or an old attack with a new twist.

I’ll keep waiting until T2 for details.

UPDATES

Some additional thoughts from other, very talented and insightful researchers, speculating on the attack vector and its novelty, as well as defenses:

One Response | Add your own



Comment Post by: Ubuntu Security » Blog Archive » DoS Me Like It’s 1996 — October 9th, 2008 @ 9:51 pm EST  Reply

[...] latest, we should give some credit to BindView RAZOR’s Naptha research from 2000, as noted by Jose Nazario. So-called Naptha attacks are any mechanism that forces the victim’s TCP/IP stack to consume [...]

Leave a Comment