5 ms·
I read the whole thing and that is the line that stuck out most to me. This could very scary. It could be used to bring down a webserver
by thechut 14y ago
I read the whole thing and that is the line that stuck out most to me. This could very scary. It could be used to bring down a webserver
- EvanAnderson 14y agoIt sounds like the vulnerability could be used to bring down any machine you can send an arbitrary Ethernet frame to. (I immediately wonder if it works for broadcast frames? Sounds like a way to take down a LAN full of machines quickly if it does.) Edit: Per http://www.kriskinc.com/intel-pod http://www.kriskinc.com/intel-pod it does work on broadcast frames. Yikes!
- samstave 14y agoHeh, yeah and he pretty much gives all the info on how to create the attack. The test would be to find out how common that particular NIC is out there - and grab a few and test out his method. Looks like it would be fairly trivial to setup duplication given the author did all the heavy lifting in finding this. Putting a small AWS bot-net up that just sweeps massive IP blocks would be easy - heck you could do it really easily from a single machine, it would seem. If you can take out a machine with a single packet....
- jacquesm 14y agoJust to be on the safe side I just checked all my machines, the majority have broadcom cards, the three that have intel cards are all another type. I think I'll sleep soundly tonight but I felt compelled to check.
- samstave 14y agoThat was a very responsible thing to do. :)
- jacquesm 14y agoProfessional paranoia. Stuff like this is really no fun at all. off-topic: A long time ago we found that a certain ping packet would be dropped with about 30%, which in turn triggered a monitoring system to register 'server down' when enough packets in a row were missed. This would happen about once every day or so, leading to an operator being paged (usually at 3am). Very annoying problem and incredibly hard to debug. We'd replaced just about every piece of hardware except for a stupid little T-connector. My buddy Jasper and me looked at it and we both more or less at the same time said 'it can't be'. We swapped out the T-connector, problems solved. It took the better part of a day to nail that one, I still remember the hostname (chopper) of the SGI box that the thing was connected to (SGI Challenge, an Indy sold as a server with one of those silly thinnet adapters dangling off the back, even though it had a UTP connector too). Some bugs... I can't say I'm mourning the demise of coaxial ethernet and the bus topology.
- samstave 14y agoHeh, I have had experiences like that with T-connectors. Heck, even just a few months ago I spent 2 hours troubleshooting a 10G fiber connection on all brand new gear before swapping out the brand-new cisco 10G SR SFP module which was DOA. Thinking the same exact thing after swapping out everything else, including all patch cords on both ends "It can't possible be this SFP module" Yup.
- martinced 14y ago"he pretty much gives all the info on how to create the attack" And the more disruptive the attack the better. Because it shall help have better process put into place, at every level, to mitigate such issues in the future. The last thing I want is a deadly packet not breaking havoc only because it's payload is not known. If a single packet can bring down a big part of the net, then by all means make it happen and make it as bad you can. And then we can start thinking about how to build a more reliable and more secure net.
- samstave 14y agoOh, I agree. I have a total digital schadenfreude for such things, except for stuxnet and duqu which are evil and scary.