[VulnDiscuss] Re: Etherleak: Ethernet frame padding information leakage (A010603-1)

"Ofir Arkin" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <000401c2b7b8$860623d0$420208d5@joshua>
>It seems that this bug isnt new. 
>"remote memory reading through tcp/icmp" 
>http://cert.uni-stuttgart.de/archive/bugtraq/2002/01/msg00239.html 

>It appears that the causes wasnt so clear. 

Before crying wolf it is advised that next time you would read the
paper...

If you have read the paper (and understood it) you could see that the
referenced link does not relate to the bug we have discovered.

Just for general knowledge - An ICMP error message includes at least (if
there is no data carried by the offending packet) 48 data bytes (20
bytes of the IP Header + 8 bytes of the ICMP Header + 20 bytes of the IP
Header of the packet which have caused the error message). 

The bug referenced in the link is not the same bug we have discovered
since we are dealing with packets which are less than 46 data bytes... -
So how would this be relating to the bug?

The bug you have referenced to is a different bug in which Linux,
_specifically_, is _adding_ information to an ICMP error message (ICMP
Time Exceeded in transit and by the way to other error messages as well)
which has been discovered long before the reference you have linked to.


Next time, try to read the paper before you suggest things...


Ofir Arkin [[email protected]]
Founder
The Sys-Security Group
http://www.sys-security.com
PGP CC2C BE53 12C6 C9F2 87B1 B8C6 0DFA CF2D D360 43FA
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.