Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
At the 26th Chaos Communication Congress (26C3) in Berlin, security researcher Fabian Yamaguchi demonstrated a number of vulnerabilities that can apparently be found in many average communication networks and affect all levels from the access layer to the application layer. Attackers exploit many minor design flaws which allow "dangerous attacks" when combined, explained the Berlin-based security expert who last year investigated vulnerabilities in the basic TCP internet protocol. Overall, the "bugs" can reportedly be exploited to hijack a proxy server such as Squid and control all of the network traffic that flows through it.. Yamaguchi explained that typical corporate networks, for instance, include a "demilitarised zone" (DMZ) with restricted access to the connected servers. Attackers who compromise a system within this zone have no access to local networks yet, said the researcher. This requires getting over a firewall, he added. It therefore makes little sense to directly attack a machine installed in this zone, said Yamaguchi. A detour via one of the system's clients, which are surrounded by a "zoo of technologies" such as Flash, media players or chat systems, tends to be the much more promising option. To demonstrate, "fabs" chose the Pidgin instant messaging software, where emoticons in MSN Chat are apparently known to be particularly vulnerable to attacks. According to the security expert, the software's "shoddy" protocol replaces character strings and word strings with images, allowing a more or less unrestricted variety of symbols to be displayed. The protocol's flawed encoding of a text in binary enabled Yamaguchi to download an executable program and eventually gave the researcher a first foothold in the network. The link for this article located at H Security is no longer available. . Yamaguchi explained that typical corporate networks, for instance, include a 'demilitarised zone' (D. chaos, communication, congress, (26c3), berlin, security, researcher, fabian, yamaguchi. . Anthony Pell
VANCOUVER, British Columbia--Widespread reports about a flawed communications protocol making the Internet vulnerable to collapse were overblown, according to the researcher credited with uncovering the security problem. A flaw in the most widely used protocol for sending data over the Net--TCP, or the Transmission Control Protocol--was addressed by most large Internet service providers during the last two weeks and presents little danger to major networks, said Paul Watson, a security specialist for industry automation company Rockwell Automation. If left unfixed, the weakness could have allowed a knowledgeable attacker to shut down connections between certain hardware devices that route data over the Net. . . .. VANCOUVER, British Columbia--Widespread reports about a flawed communications protocol making the Internet vulnerable to collapse were overblown, according to the researcher credited with uncovering the security problem. A flaw in the most widely used protocol for sending data over the Net--TCP, or the Transmission Control Protocol--was addressed by most large Internet service providers during the last two weeks and presents little danger to major networks, said Paul Watson, a security specialist for industry automation company Rockwell Automation. If left unfixed, the weakness could have allowed a knowledgeable attacker to shut down connections between certain hardware devices that route data over the Net. "The actual threat to the Internet is really small right now," Watson said on Wednesday. "You could have isolated attacks against small networks, but they would most likely be able to recover quickly." Watson was responding to news reports that ran Tuesday, after Britain's national emergency response team, the National Infrastructure Security Co-ordination Centre, released an advisory about the issue based on his research. Watson, who's scheduled to present that research here at the CanSecWest 2004 conference this week, referred to the media reaction as an "inordinate level of attention in respectto the amount of risk." At greatest risk, he said, may be e-commerce sites that manage their own routers--those sites may not believe they're vulnerable to attack and may not have implemented a fix. Sites that have routers that share information on the most efficient paths through the Internet--using the Border Gateway Protocol, or BGP--are most vulnerable to the attacks. . Claims regarding vulnerabilities in the TCP connection system are exaggerated, asserts expert; little risk to core infrastructures currently.. Tcp Threat Assessment, Communications Protocol Flaws, Security Risk Analysis. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.