Home > technical > DoS through TCP sequence number vulnerability

DoS through TCP sequence number vulnerability

SecurityFocus is reporting that multiple vendors are affected by a newly found design flaw in common TCP implementations.  The flaw allows remote attackers to effectively end a TCP session by sending an RST or SYN packet with an approximated TCP sequence number and a forged source IP address.  This would reset the TCP connection and effectively cause a denial of service attack.  Microsoft is one of a long list of vendors on the affected list so you can bet the eggheads at SlashNot are going to highlight their name among them all.

No related posts.

Categories: technical Tags: , ,
  1. December 21st, 2009 at 08:13 | #1

    somehow that exploit seems like old news … years old … or is this a new flavor?

  1. No trackbacks yet.