Most Popular Stories
- CMIS slowly begins to bake
- One on One with Daniel Tunkelang of Endeca
- Which companies are more recession proof?
- QUICKLINKS: Cisco and Apple talking again; IBM comes on-board for WiMAX; Broadcom releases chip with FM, WiFi and Bluetooth
- Analyst: Apple will launch netbook competitor in response to slowdown
- EMC announces Captiva 6
- U.S. military bans USB flash drives and removable media
- Analyst: Apple will launch netbook competitor in response to slowdown
- Report claims that Google is snipping 10,000 jobs
- CMS Watch says enterprise search vendors are opening up
- IT users are frustrated by failure
- Using text messages to remotely disable Lenovo ThinkPads
Events
- Gilbane Conference Boston
December 2-4, 2008 — Westin Copley Place, Boston MA
Sponsored Links
Free Newsletter
Popular Topics
Whitepapers
- The Definitive IP Address Management (IPAM) Intelligence Whitepaper
- HIPAA Security Provisions
- How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
- Service Oriented Architecture
- Collaboration and Social Media: Taking Stock of Today's Experiences and Tomorrow's Opportunities
- The Case for an Untethered Enterprise
Newly discovered vulnerabilities in TCP could take down data centers
![]()
Vendors are scrambling to rectify a bag of nasty vulnerabilities in TCP that appear to have the potential to cause an Internet meltdown. Discovered by Robert Lee and Jack Louis from security vendor Outpost 24, the flaws allow a denial of service (DOS) attack that can be launched to cripple servers running various operating systems, as well as firewalls. Aside from the fact that very little bandwidth (and only a few seconds) is required for a successful attack, it is scary to think that affected systems could well remain disabled even after the cessation of an attack run. Taken together, it certainly is well within the realm of plausibility to take down an entire data center from a single terminal.
Everything started off when Louis noticed some anomalous situations in which machines would stop responding in some very specific circumstances when scanned. Further experimentation and research yielded a tool called "sockstress," which does the dirty work mentioned above. Elaborating, Lee noted that the vulnerability stems from "at least five", and perhaps as many as 30 different problems, which logically means short-term solutions or temporary mitigations are unlikely.
What really caught my attention here was that even IPv6 services are not spared, since they still sit on top of the vulnerable TCP stack. Indeed, they are more affected due to the fact that they require more resources to run.
Folks, it has been almost a quarter of a century since TCP/IP saw widespread use as a required protocol of ARPANET in 1983. If the extent of the potential damage only just discovered is even partially accurate, this incident will only serve to confirm that security is a journey, not a destination. - Paul
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





