Beck, Aaron wrote:
[snip, line breaks woulda been nice, BTW]

However, most of the other protocols have -some- form of integrity checking - whether its on the data itself (as in DNS Zone Transfers), or higher up in the protocol stack (such as SSH and TCP Encapsulation of IPSEC).

Whatever you do at the application layer doesn't change this vulnerability. SSH is just as vulnerable as telnet or FTP. The attacker can reset the TCP connection, and therefore the SSH session riding on TCP, just as easily.

IPsec, either AH or ESP, do virtually eliminate any possibility of the attack,
but IPsec takes place "under" TCP. IPsec protects or "encapsulates" TCP. But
something like "TCP encapsulation of IPsec" _would_ be vulnerable to being
reset. How disruptive this is to a kludge like IPsec over TCP depends on
just how ugly the hackish implementation is.

Another way to protect TCP is with the MD5 Signature TCP option, RFC2385. This
is a modification to TCP itself. But that is not widely deployed anywhere
accept in BGP speaking routers.
--
Crist J. Clark                               [EMAIL PROTECTED]
Globalstar Communications                                (408) 933-4387

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to