FreeBSD syncookies TCP Initial Sequence Number Weakness
BID:6920
Info
FreeBSD syncookies TCP Initial Sequence Number Weakness
| Bugtraq ID: | 6920 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Feb 24 2003 12:00AM |
| Credit: | This issue was reported in a FreeBSD Security Advisory. |
| Vulnerable: |
FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 |
| Not Vulnerable: | |
Discussion
FreeBSD syncookies TCP Initial Sequence Number Weakness
The FreeBSD implementation of syncookies are prone to brute force attacks. This is due to generated keys being 32 bits in length.
It is possible to generate valid ISN keys using a compromised syncookie. This may allow an attacker to spoof TCP connections that may be used to bypass IP-based access control lists.
Other attacks, including denial of service attacks, are also possible.
The FreeBSD implementation of syncookies are prone to brute force attacks. This is due to generated keys being 32 bits in length.
It is possible to generate valid ISN keys using a compromised syncookie. This may allow an attacker to spoof TCP connections that may be used to bypass IP-based access control lists.
Other attacks, including denial of service attacks, are also possible.
Exploit / POC
FreeBSD syncookies TCP Initial Sequence Number Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FreeBSD syncookies TCP Initial Sequence Number Weakness
Solution:
FreeBSD has released an advisory. Users are advised to apply the included patches or to upgrade systems via CVS. Further information is available in the referenced advisory.
The following patches are available:
FreeBSD FreeBSD 4.6
FreeBSD FreeBSD 4.7
FreeBSD FreeBSD 5.0
Solution:
FreeBSD has released an advisory. Users are advised to apply the included patches or to upgrade systems via CVS. Further information is available in the referenced advisory.
The following patches are available:
FreeBSD FreeBSD 4.6
-
FreeBSD syncookie.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:03/syncookie.patc h
FreeBSD FreeBSD 4.7
-
FreeBSD syncookie.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:03/syncookie.patc h
FreeBSD FreeBSD 5.0
-
FreeBSD syncookie.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-03:03/syncookie.patc h
References
FreeBSD syncookies TCP Initial Sequence Number Weakness
References:
References: