Researchers reveal gaping IP flaw

Researchers reveal gaping IP flaw

Staff Writer  |   October 03, 2008
Thumbnail: 

Researchers at Finnish security firm Outpost 24 have revealed a flaw in the Internet Protocol (IP) that can disrupt any computer or server, according to a report by Webwereld Netherlands.

Apparently the flaw has been known to some for years. Now the researchers hope that an open admission will help them find a solution more quickly.

The flaw allows attackers to cripple computers and servers by sending a few specially formed TCP/IP packets. The result can be compared to a denial of service attack, in which networks are flooded with traffic, but in this case, as few as ten packets per second are needed to bring down a service it seems.

This latest revelation comes hard on the heels of the Domain Name Server (DNS) security flaw being made public earlier this year, which is still a cause for concern. The DNS problem means that users can redirected to copycat sites of the ones they actually want. Once they enter passwords and other information, phishers can access their actual bank and other accounts.

A number of products have hit the market in an attempt to address the DNS problem, such as the DNS Firewall introduced by Infoblox on Tuesday. This is an addition to its line of core network services appliances designed to prevent so-called cache poisoning - the interception of requests for information and redirecting of traffic.

Infoblox is working with Dan Kaminsky, who is credited with identifying the DNS problem, to establish how many vulnerable systems have been patched so far. Anecdotal evidence suggests the number is as low as 30%.

Infoblox and Kaminsky are to publish the results of a formal, global survey in November.

The really bad news though is that firewalls and other intrusion prevention mechanism don't help with the IP flaw because, by definition, they support TCP/IP and are therefore vulnerable.
 
See here
for the full story.

Tell Us What You Think

Add comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

Voices_tabs

Nicole McCormick
As opposition still ponders its policy
Robert Clark
Nokia lacks confidence in its OS and CEO
Santosh Sathanur/Ovum
As do enterprise services
Evan Kirchheimer/Ovum
Operators are turning to the technology with renewed vigor
Martin Creaner
The next evolution of NGOSS
John C. Tanner
It's not clear how consumers benefit from industry-preferred model of exclusive TV content contracts

Video from Telecom Channel

Converged billing still top concern -- Cerillion
The industry has attempted to move to simpler billing models but complexity still dominates, driven by product bundling and data packaging.    
 

businessweek_industryview

Ville Heiskanen, Peter Elstrom
FCC says 14-24m unlikely to get higher-speed connection any time soon
Sampath Paranavitane, hSenid Mobile
The foundation of a loyal following around self-created applications

Frontpage Content by Category

Telecomasia.net's most popular news stories, blogs, analysis and features in the first six months of 2010

MWC2010 List

MOBILE WORLD CONGRESS 2010
HTC guns for top 3 smartphone makers
Powermat wants to charge your desktop
Femtos outlook improves as cellcos seek offload options
Cheaper smartphones key to broadband takeup

lighter_side_telecom_career

Staff writer
Turning your mobile device into its own mouse
Dylan Bushell-Embling
Responding to panel suggestions for turning around the PSUs