Internet flaw poses potential security problem

The Computer Emergency Response Team (CERT) have warned companies of security problems caused by a fundamental flaw in the way PCs and servers talk to each other across the Internet.

Two papers providing detailed analysis of the vulnerability were released recently by security firms Guardent and BindView.

The vulnerability occurs in the so-called "initial sequence numbers," or ISN, computers use to reconstruct data sent over the Internet back into the original file. While some details had been released three months ago, the two papers point out deficiencies in the way such numbers are created by many operating systems, such as Microsoft's Windows 95 and Window 98 and Sun Microsystems' Solaris version of Unix.

The problem, said Jeffrey S. Havrilla, Internet security analyst for the CERT Coordination Centre, a computer security organisation based at Pittsburgh's Carnegie Mellon University, is that the Internet's fundamental data control mechanism known as TCP (transfer control protocol) was meant to improve reliability, not ensure security.

"TCP was designed to be a reliable protocol, and one to insure that it was designed to be somewhat predictable," he said.

That predictability could let an attacker guess the next number in a sequence, allowing him or her to send data to a victim's computer and masquerade as a legitimate connection. That could allow a network intruder to grab e-mail, monitor a chat exchange or simply use the connection to start a more complete compromise of the system.

The most recent vulnerability in the way that many operating systems generate the initial sequence numbers was originally outlined by Guardent, which only recently released its research on the topic.

But using the new method will not be easy, Havrilla said.

"In order to use the new vulnerability, you need to have a new set of tools to do the statistical analysis, and we haven't seen that sort of intelligence in the tools to date," he said.

According to the analysis completed by BindView, operating systems such as the Linux 2.2 kernel and the most recent version of OpenBSD create strong ISNs, while operating systems such as Windows 95, Windows 98, older versions of Windows NT, AIX and HPUX have relatively weak procedures for generating ISNs.

The latter operating systems could be exploited by an attack using the new vulnerability.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured