April 13, 2005

Industry reels from IP flaw

IP flaw could allow attacks on routers and Internet software

The U.K.'s National Infrastructure Co-Ordination Centre (NISCC) has warned of a flaw in Internet Protocol (IP) that could allow significant attacks on a wide range of products, including routers and Internet software from Microsoft, Cisco Systems, IBM, Juniper Networks, and others.

While the flaw in ICMP, IP's control protocol, will be only moderately critical for some vendors' products, in others it could allow a denial-of-service attack with medium-term effects, effectively putting the system out of commission for a significant period of time while it is reset, the NISCC said in an advisory. In other products, attacks could merely slow down traffic or result in short-term denial-of-service.

Because the problems with ICMP have been circulating in the security community for some time, some products have already been modified to block the attacks; for example many Linux products mitigate or eliminate the problems, the NISCC said. The organization is publishing an updated list of affected vendors in a PDF version of the advisory.

"Most vendors include support for this protocol in their products and may be impacted to varying degrees," the agency said in its advisory. One of the ICMP vulnerabilities, termed a TCP blind connection-reset vulnerability, could mean significant problems for some implementations of the Border Gateway Protocol (BGP), one of the Internet's core protocols, according to the advisory. "BGP relies on a persistent TCP connection between BGP peers; resetting the connection can result in medium term unavailability due to the need to rebuild routing tables and route flapping," the NISCC said.

Cisco issued an advisory detailing which of its products are affected by the ICMP vulnerabilities and how to mitigate problems; affected products include Cisco Content Services Switch 11000 Series, Global Site Selector 4480, and various versions of IOS.

One of this week's Microsoft security patches, Security Bulletin MS05-019, updates Windows software for TCP/IP to fix the TCMP problems. IBM said its AIX operating system is affected and that it will give details in an advisory on its Web site. Juniper Networks said its M-series and T-series routers running certain releases of JUNOS software are affected and said it would make more information available on its site. Red Hat said its Enterprise Linux products are unaffected by two of the three TCMP vulnerabilities, and are only partly affected by the third.

The problems are described in a recent Internet-Draft paper by Fernando Gont, a member of the TCMP working group at the IETF (Internet Engineering Task Force), and include three types of potential attacks for slowing traffic or denial of service. The first could reset an established TCP connection using ICMP packets to simulate a hard error condition, the second could slow down traffic using forged ICMP packets, and the third could slow traffic using ICMP Source Quench packets.

Close

On Twitter now

Networking

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Networking Resource Alerts

Subscribe to the Technology: Networking Newsletter

The one-stop resource center for IT professionals.

©1994-2009 Infoworld, Inc.