Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
BID:2682
Info
Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
| Bugtraq ID: | 2682 |
| Class: | Design Error |
| CVE: |
CVE-2001-0328 CVE-2001-0288 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 14 2001 12:00AM |
| Updated: | Oct 26 2016 05:08AM |
| Credit: | Originally discovered by Tim Newsham <[email protected]>. |
| Vulnerable: |
Sun Solaris 7.0 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 OpenBSD OpenBSD 2.8 Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows NT 4.0 SP6 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 Microsoft Windows 98SE Microsoft Windows 98 Microsoft Windows 95 Linux kernel 2.1 .x Linux kernel 2.0 .x IBM AIX 4.3 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.0 FreeBSD FreeBSD 4.2 -STABLEpre050201 FreeBSD FreeBSD 3.5 -STABLEpre050201 Cisco IOS 12.1YD Cisco IOS 12.1YC Cisco IOS 12.1YB Cisco IOS 12.1YA Cisco IOS 12.1XZ Cisco IOS 12.1XY Cisco IOS 12.1XX Cisco IOS 12.1XW Cisco IOS 12.1XV Cisco IOS 12.1XU Cisco IOS 12.1XT Cisco IOS 12.1XS Cisco IOS 12.1XR Cisco IOS 12.1XQ Cisco IOS 12.1XP Cisco IOS 12.1XM Cisco IOS 12.1XL Cisco IOS 12.1XK Cisco IOS 12.1XJ Cisco IOS 12.1XI Cisco IOS 12.1XH Cisco IOS 12.1XG Cisco IOS 12.1XF Cisco IOS 12.1XE Cisco IOS 12.1XD Cisco IOS 12.1XC Cisco IOS 12.1XB Cisco IOS 12.1XA Cisco IOS 12.1T Cisco IOS 12.1EX Cisco IOS 12.1EC Cisco IOS 12.1E Cisco IOS 12.1DC Cisco IOS 12.1DB Cisco IOS 12.1DA Cisco IOS 12.1CX Cisco IOS 12.1AA Cisco IOS 12.1 Cisco IOS 12.0XV Cisco IOS 12.0XU Cisco IOS 12.0XS Cisco IOS 12.0XR Cisco IOS 12.0XQ Cisco IOS 12.0XP Cisco IOS 12.0XN Cisco IOS 12.0XM Cisco IOS 12.0XL Cisco IOS 12.0XK Cisco IOS 12.0XJ Cisco IOS 12.0XI Cisco IOS 12.0XH Cisco IOS 12.0XG Cisco IOS 12.0XF Cisco IOS 12.0XE Cisco IOS 12.0XD Cisco IOS 12.0XC Cisco IOS 12.0XB Cisco IOS 12.0XA Cisco IOS 12.0WT Cisco IOS 12.0W5 Cisco IOS 12.0T Cisco IOS 12.0SX Cisco IOS 12.0ST Cisco IOS 12.0SL Cisco IOS 12.0SC Cisco IOS 12.0S Cisco IOS 12.0DC Cisco IOS 12.0DB Cisco IOS 12.0DA Cisco IOS 12.0 Cisco IOS 11.3WA4 Cisco IOS 11.3T Cisco IOS 11.3NA Cisco IOS 11.3MA Cisco IOS 11.3HA Cisco IOS 11.3DB Cisco IOS 11.3DA Cisco IOS 11.3AA Cisco IOS 11.3(2)XA Cisco IOS 11.3 Cisco IOS 11.2WA3 Cisco IOS 11.2SA Cisco IOS 11.2P Cisco IOS 11.2GS Cisco IOS 11.2F Cisco IOS 11.2BC Cisco IOS 11.2(9)XA Cisco IOS 11.2(4)XA Cisco IOS 11.2 Cisco IOS 11.1IA Cisco IOS 11.1CT Cisco IOS 11.1CC Cisco IOS 11.1CA Cisco IOS 11.1AA Cisco IOS 11.1 Cisco IOS 11.0 BSDI BSD/OS 4.0 BSDI BSD/OS 3.0 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 Apple Mac OS 9 9.1 Apple Mac OS 9 9.0.4 Apple Mac OS 9 9.0 Apple Mac OS 8 8.6 Apple Mac OS 8 8.5 Apple Mac OS 8 8.1 Apple Mac OS 8 8.0 Apple Mac OS 7 7.6.1 Apple Mac OS 7 7.6 Apple Mac OS 7 7.5.3 Apple Mac OS 7 7.5.2 Apple Mac OS 7 7.5.1 Apple Mac OS 7 7.1.2 Apple Mac OS 7 7.1 Apple Mac OS 7 7.0.1 Apple Mac OS 7 7.0 ABB RTU500 Series 11.3 |
| Not Vulnerable: |
Linux kernel 2.2 .x ABB RTU500 Series 11.4.1 |
Discussion
Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
Over the past several years, a variety of attacks against TCP initial sequence number (ISN) generation have been discussed.
A vulnerability exists in some TCP/IP stack implementations that use random increments for initial sequence numbers. Such implementations are vulnerable to statistical attack, which could allow an attacker to predict, within a reasonable range, sequence numbers of future and existing connections.
By predicting a sequence number, several attacks could be performed; an attacker could disrupt or hijack existing connections, or spoof future connections.
Over the past several years, a variety of attacks against TCP initial sequence number (ISN) generation have been discussed.
A vulnerability exists in some TCP/IP stack implementations that use random increments for initial sequence numbers. Such implementations are vulnerable to statistical attack, which could allow an attacker to predict, within a reasonable range, sequence numbers of future and existing connections.
By predicting a sequence number, several attacks could be performed; an attacker could disrupt or hijack existing connections, or spoof future connections.
Exploit / POC
Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
Solution:
Under Solaris 7, it has been suggested that the feasibility of this attack is eliminated by setting "tcp_strong_iss=2".
SGI has suggests the tcpiss_md5 kernel parameter may eliminate this vulnerability. Details are available in the SGI advisory 20020303-01-A listed as a reference. This parameter is disabled by default.
SGI has released a second advisory for this issue which contains fixes for the IRIX operating system. Users are advised to upgrade their systems as soon as possible.
Users of HP-UX 11.0 may install patch PHNE_22397 to enable HP randomization of initial sequence numbers.
Users of HP-UX 11.0, 11.04 and 11.11 may enable RFC 1948 compliant randomization through patches PHNE_26771, PHNE_26101, or PHNE_25644 respectively. Once patched, the following shell command must be executed by root:
ndd -set /dev/tcp tcp_isn_passphrase <secret passphrase>
Where <secret passphrase> is any length character string. Only the first 32 characters will be retained. If the passphrase is changed the system should be rebooted.
Several vendors have released kernel patches and upgrades which address this issue:
Cisco IOS 12.0SC
Cisco IOS 12.0XA
Cisco IOS 12.1XQ
Cisco IOS 12.1XJ
Cisco IOS 12.1XI
Cisco IOS 12.1XS
Cisco IOS 12.0XB
Cisco IOS 12.1XV
Cisco IOS 11.0
Cisco IOS 12.0XG
Cisco IOS 12.1YD
Cisco IOS 12.0XS
Cisco IOS 12.1XX
Cisco IOS 11.3
Cisco IOS 12.1XM
Cisco IOS 12.0XK
Cisco IOS 12.1XY
Cisco IOS 12.1XL
Cisco IOS 12.1XT
Cisco IOS 11.1CC
Cisco IOS 11.1CA
Cisco IOS 11.2P
Cisco IOS 12.0XH
Cisco IOS 12.0DC
Cisco IOS 12.0T
Cisco IOS 11.3NA
Cisco IOS 11.2
Cisco IOS 11.3AA
Cisco IOS 12.1YA
Cisco IOS 12.1YB
Cisco IOS 12.1XG
Cisco IOS 11.1
Cisco IOS 11.2GS
Cisco IOS 11.3(2)XA
FreeBSD FreeBSD 3.5 -STABLEpre050201
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14 m
Solution:
Under Solaris 7, it has been suggested that the feasibility of this attack is eliminated by setting "tcp_strong_iss=2".
SGI has suggests the tcpiss_md5 kernel parameter may eliminate this vulnerability. Details are available in the SGI advisory 20020303-01-A listed as a reference. This parameter is disabled by default.
SGI has released a second advisory for this issue which contains fixes for the IRIX operating system. Users are advised to upgrade their systems as soon as possible.
Users of HP-UX 11.0 may install patch PHNE_22397 to enable HP randomization of initial sequence numbers.
Users of HP-UX 11.0, 11.04 and 11.11 may enable RFC 1948 compliant randomization through patches PHNE_26771, PHNE_26101, or PHNE_25644 respectively. Once patched, the following shell command must be executed by root:
ndd -set /dev/tcp tcp_isn_passphrase <secret passphrase>
Where <secret passphrase> is any length character string. Only the first 32 characters will be retained. If the passphrase is changed the system should be rebooted.
Several vendors have released kernel patches and upgrades which address this issue:
Cisco IOS 12.0SC
Cisco IOS 12.0XA
Cisco IOS 12.1XQ
Cisco IOS 12.1XJ
Cisco IOS 12.1XI
Cisco IOS 12.1XS
Cisco IOS 12.0XB
Cisco IOS 12.1XV
Cisco IOS 11.0
Cisco IOS 12.0XG
Cisco IOS 12.1YD
Cisco IOS 12.0XS
Cisco IOS 12.1XX
Cisco IOS 11.3
Cisco IOS 12.1XM
Cisco IOS 12.0XK
Cisco IOS 12.1XY
Cisco IOS 12.1XL
Cisco IOS 12.1XT
Cisco IOS 11.1CC
Cisco IOS 11.1CA
Cisco IOS 11.2P
Cisco IOS 12.0XH
Cisco IOS 12.0DC
Cisco IOS 12.0T
Cisco IOS 11.3NA
Cisco IOS 11.2
Cisco IOS 11.3AA
Cisco IOS 12.1YA
Cisco IOS 12.1YB
Cisco IOS 12.1XG
Cisco IOS 11.1
Cisco IOS 11.2GS
Cisco IOS 11.3(2)XA
FreeBSD FreeBSD 3.5 -STABLEpre050201
-
FreeBSD 3.5.1 tcp-isn-3.5.1-rel.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:39/tcp-isn-3.5.1- rel.patch -
FreeBSD 3.5.1 tcp-isn-3.5.1-stable.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-01:39/tcp-isn-3.5.1- stable.patch
SGI IRIX 6.5.14 f
SGI IRIX 6.5.14 m
References
Multiple Vendor TCP Initial Sequence Number Statistical Vulnerability
References:
References:
- Strange Attractors and TCP/IP Sequence Number Analysis (Bindview Razor Team)
- Vulnerability Note VU#498440 (CERT)
- TCP Predictability Vulnerability in RTU500 series (ABB)