Vendors rush to fix bug that could crash Internet systems
Flaw in TCP/IP could easily knock servers offline, researchers say
October 3, 2008 12:00 PM ETIDG News Service - Internet infrastructure vendors are working on patches for a set of security flaws that could help hackers knock servers offline with very little effort.
The security community has been buzzing about the bugs since Tuesday, when security researcher Robert Hansen discussed the problem on his blog.
Technical details on the vulnerabilities have not been released, but the security experts who discovered the problem, Robert Lee and Jack Louis of security vendor Outpost24, say that they can knock Windows, Linux, embedded systems and even firewalls offline with a denial-of-service (DOS) attack. The flaws lie in the TCP/IP software used by these systems to send data over the Internet.
Lee and Louis first discussed the problem last week at a conference in Amsterdam, and many of the affected vendors are working on patching the issue with help from the Finnish national Computer Emergency Response Team, said Lee, who spent most of Wednesday and Thursday explaining the issue.
"The vendors who are capable and responsible for creating solutions are in the loop," said Lee, Outpost24's chief security officer. "The public message here is, 'Chill out -- the people who need to be involved are involved.'"
He could not say how long it would take to fix the problem.
In a statement, Microsoft Corp. said it is investigating the matter and "unaware of any attacks trying to use the claimed vulnerability or of customer impact."
But according to Hansen, if attacks did appear, they could be serious. That's because they can be launched with very little bandwidth and targeted machines could often remain disabled even after the DOS attack has stopped.
"This appears not to be a single bug, but in fact at least five, and maybe as many as 30 different potential problems," Hansen, CEO of SecTheory, wrote on his blog. "They just haven't dug far enough into it to really know how bad it can get. The results range from complete shutdown of the vulnerable machine to dropping legitimate traffic."
Lee and Louis are set to discuss the flaws two weeks from now at the T2 conference in Helsinki, Finland, but they will not release additional details if the flaws remain unpatched, Lee said.
Arbor Networks Chief Security Officer Danny McPherson said that while talking about the flaw without revealing the technical details may generate buzz for Lee and Louis' conference presentation, it provides little value to users. "These partial disclosures really do little more than trigger a slew of skepticism," he said via instant message.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Internet infrastructure
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

