<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://sciencex2.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>outpost24</title>
 <link>http://sciencex2.org/en/taxonomy/term/3283</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Sockstress:  An Internet Vulnerability That May Create the Date the Net Stood Still?</title>
 <link>http://sciencex2.org/en/node/52736</link>
 <description>&lt;h3 class=&quot;field-label&quot;&gt;Description&lt;/h3&gt;
&lt;div class=&quot;content&quot;&gt;
   &lt;p&gt;Jack Louis and Robert Lee, from Outpost24 (&lt;a href=&quot;http://www.outpost24.com/&quot; title=&quot;http://www.outpost24.com/&quot;&gt;http://www.outpost24.com/&lt;/a&gt;), are scheduled to give a talk at the T2&#039;08 Information Security Conference in Finland later this month giving details on a new, and dangerous, denial of service attack that uses TCP state table manipulation. The attack is unique in that it is cross platform and requires very little bandwidth to be executed.[1] This attack also has a prolonged impact on the hardware that lasts beyond the denial of service. As a blogger from a recent talk from Louis and Lee wrote, &amp;quot;After this introduction it was time for them to show their application Sockstress. Unfortunately they couldn&amp;rsquo;t disclose any technical details about it but they ran two demos and it was quite amazing.Exploiting a vulnerability they showed us how they brought down port 80 on a web server (or actually the presentation laptop) in a matter of seconds. A typical Denial of Service attack. The next demo was even better. The started playing music on the very same laptop and then started Sockstress. After about two minutes the music wouldn&amp;rsquo;t play the way it was supposed to. It was slowed down, the CPU was at 100% etc. They then stopped sockstress but the machine never came back. It kept misbehaving even though the attack was over. What was really interesting was that both these attacks only sent 4 packages each second to the server machine. That&amp;rsquo;s nothing and could be done on a 56k modem. Scary but cool.&amp;quot; Louis and Lee have contacted vendors regarding the various bugs they have found which allow for this exploit but aren&#039;t releasing technical details at this time due to the fact that there are currently no short-term fixes.[3] Concern has been expressed in the security community that just the simple talks given thus far may be enough of a recipe for a low-level hacker to easily replicate the attack.&lt;/p&gt;
&lt;div class=&quot;og_rss_groups&quot;&gt;&lt;ul class=&quot;links&quot;&gt;&lt;li class=&quot;first last og_links&quot;&gt;&lt;a href=&quot;/en/node/13855&quot; class=&quot;og_links&quot;&gt;Computer &amp;amp; Information Science&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;field field-type-text field-field-source&quot;&gt;
  &lt;h3 class=&quot;field-label&quot;&gt;Source&lt;/h3&gt;
  &lt;div class=&quot;field-items&quot;&gt;
      &lt;div class=&quot;field-item&quot;&gt;&lt;p&gt;[1]&quot;Jack C. Louis and Robert E. Lee to talk about New DoS Attack Vectors&quot;, T2&#039;08 Conference, August 27, 2008, Jack C. Louis and Robert E. Lee to talk about New DoS Attack Vectors&lt;br /&gt;
[2]&quot;Sec-T, Day 1&quot;, Norden Felt, September 12, 2008, &lt;a href=&quot;http://blog.nordenfelt.com&quot; title=&quot;http://blog.nordenfelt.com&quot;&gt;http://blog.nordenfelt.com&lt;/a&gt;&lt;br /&gt;
[3]&quot;Snake Bytes:  New DOS Attack is a Killer&quot;, RSnake, darkREADING, September 30, 2008, &lt;a href=&quot;http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;amp;doc_id=164939&amp;amp;WT.svl=tease2_2&quot; title=&quot;http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;amp;doc_id=164939&amp;amp;WT.svl=tease2_2&quot;&gt;http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;amp;doc_id=164939&amp;amp;WT.svl=tease2_2&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;
</description>
 <comments>http://sciencex2.org/en/node/52736#comments</comments>
 <category domain="http://sciencex2.org/en/taxonomy/term/3281">denial of service</category>
 <category domain="http://sciencex2.org/en/taxonomy/term/3263">internet vulnerability</category>
 <category domain="http://sciencex2.org/en/taxonomy/term/3284">jack louis</category>
 <category domain="http://sciencex2.org/en/taxonomy/term/3283">outpost24</category>
 <category domain="http://sciencex2.org/en/taxonomy/term/3285">robert lee</category>
 <category domain="http://sciencex2.org/en/taxonomy/term/3282">sockstress</category>
 <group domain="http://sciencex2.org/en/node/15121">Ethics in Science</group>
 <group domain="http://sciencex2.org/en/node/13855">Computer &amp;amp; Information Science</group>
 <pubDate>Thu, 02 Oct 2008 12:48:48 -0700</pubDate>
 <dc:creator>Jerry Sheehan</dc:creator>
 <guid isPermaLink="false">52736 at http://sciencex2.org</guid>
</item>
</channel>
</rss>
