Vendors rush to fix critical TCP/IP bug

Internet infrastructure vendors are rushing to develop patches for a set of TCP/IP security flaws, which could help hackers knock servers offline with very little effort.

The security community has been buzzing about the bugs since Tuesday, when security researcher Robert Hansen discussed the problem on his blog.

Technical details on the vulnerabilities have not been released, but the security experts at Outpost24, who discovered the problem, Robert Lee and Jack Louis, have said that they can knock Windows, Linux, embedded systems and even firewalls offline with what's known as a denial of service (DOS) attack. The flaws lie in the TCP/IP (Transmission Control Protocol/Internet Protocol) software used by these systems to send data over the Internet.

More Here



Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

ISP denial of service attack is from Microsoft and SunMicro ?

I have been discussing these events lately, but did not pin it on Microsoft auto-update or SunMicro ISP servers. Now, I am.

What they did was to use your computer cpu chip select to stop your computer from using your cpu to initiate too many demands for link downloads. They also use chip select to stop your modem to work temporarily. In other words, they try to control traffic by disabling your computer functions, then allowing a little traffic jam and slow delivery of service.

This can only happen by ISP servers(SunMicro software) delivering trailers of codes to control your computer from accessing the ISP servers. Your action should be disabling break(ascii code 02) in your browser, so that ISP has no way to hack your computer.

The action is not malicious, and it only happens on busy hours, such as when school children went home, or stock market crashes.

And you can break the strangle hold by reconnecting your modem, change to another ISP server which is free at the connection. Or place you mouse cursor on the clicked location to get service(whenever they allow it).

Microsoft auto-update does the hogging at the beginning of your connection to the ISP. The dot net strategy will download straight for many minutes; when they should download between your use of your computer during idling time periods.

Footnote:
Out of desperation loaded modem booster, a third party software. It added a toolbar on top of Google toolbar. So far it blocked 3 more intrusions. and it adjusted some Microsoft modules. It probably use multi path to get internet downloads, to prevent ISP from hacking WinMe. A slight improvement is observed on lack of denial of service attacks since.