Major Security Vulnerability In TCP Stack

posted by Christopher on October 5, 2008

{{chris}} A major security vulnerability in TCP stacks is uncovered recently which can knock any website off line with very little effort or bandwidth.

Steve Gibson on Security Now Episode 164 recently discussed this vulnerability referred to as “sockstress”. It’s absolutely scary given the fact that unlike tradition Distributed Denial of Service attacks (DDOS) this flaw only requires a single computer with a broadband connection to take down even the mightiest of websites. The flaw also affects routers, and loadbalancers. This as unbelievable as it sounds means that even script kiddies could take down sites like www.google.com if they wanted to.

So while real hackers have developed enormous bot nets to run DDOS attacks they would only need to pointa few of these atonomous machines at a site to bring it down.

This flaw was recently announced by a security company in Europe without first announcing it to major software and hardware manufacturers – a serious mistake in my opinion.

Our concern is that we could start to see this attack in the wild and the most likely targets would be major institutions such as Google, Amazon, Ebay etc. Let’s just hope that the software and hardware manufacturers work quickly to patch their TCP stacks and prevent this situation from turning into a major disaster.

Fingers crossed.

Share and Enjoy:
  • del.icio.us
  • Facebook
  • FriendFeed
  • LinkedIn
  • StumbleUpon
  • Technorati
  • Twitter

Comments (1 Comment)

  1. deven
    December 14, 2009

    I just have to say this was potentially one of the most intelligent posts I have come across on the topic so far. I do not have any idea where you learn all of your info but up! I’m going to send some people on over to check this out. Fantastic, just plain awesome. I am have just started getting into writing articles myself, nothing remotely close to your writing potential (ha!) but I would love for you to look over my article sometime! bowfelx series 7 treadmill

Post a Comment

Your email will be kept private and will not be published