From owner-freebsd-security@FreeBSD.ORG Fri Aug 13 17:36:49 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0517A16A4CE for ; Fri, 13 Aug 2004 17:36:49 +0000 (GMT) Received: from relay.pair.com (relay.pair.com [209.68.1.20]) by mx1.FreeBSD.org (Postfix) with SMTP id 7C73D43D31 for ; Fri, 13 Aug 2004 17:36:48 +0000 (GMT) (envelope-from silby@silby.com) Received: (qmail 79771 invoked from network); 13 Aug 2004 17:36:47 -0000 Received: from niwun.pair.com (HELO localhost) (209.68.2.70) by relay.pair.com with SMTP; 13 Aug 2004 17:36:47 -0000 X-pair-Authenticated: 209.68.2.70 Date: Fri, 13 Aug 2004 12:36:48 -0500 (CDT) From: Mike Silbersack To: Steve Zweep In-Reply-To: <411CE478.3050607@borderware.com> Message-ID: <20040813123400.G1539@odysseus.silby.com> References: <411CE478.3050607@borderware.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed cc: freebsd-security@freebsd.org Subject: Re: ICMP attacks against TCP X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 13 Aug 2004 17:36:49 -0000 On Fri, 13 Aug 2004, Steve Zweep wrote: > Has anyone seen the recently published IETF draft regarding ICMP attacks > against TCP? > [http://www.ietf.org/internet-drafts/draft-gont-tcpm-icmp-attacks-00.txt] > > I'm interested in any comments as to the vulnerability of FreeBSD's TCP to > such attacks and the need for or usefulness of the various solutions proposed > in the paper. > > Thanks, all > > - Steve Back when the RST semi-blind attacks came out, I double-checked our ICMP code for the same condition. It turns out that this was fixed by one of our developers years and years ago. I can't recall the exact version of the change now, but I believe it occured around 4.1 or 4.2. So, it could use some quick review, but I think we're good here. Mike "Silby" Silbersack