Re: MPA security issues - minutes from last IETF

Caitlin Bestler <[email protected]>
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
On Jan 22, 2004, at 9:04 PM, Jim Pinkerton wrote:

>  
>
> From David’s minutes from the last IETF meeting, he states:
>
>  
>
> --> Action Item: The "dual stack" architecture that came up in the MPA
>
> draft discussion has security implications, as the point of "stack 
> switch"
>
> is an obvious place for an attacker to try something (e.g., louse up 
> the
> stack switch so that the connection has to be abandoned).  MPA draft 
> authors
> to look into this and post results of this investigation to list.
>
>  
>
> Can the MPA authors comment on where we are at in terms of this action 
> item?
>
>  
>


Sending a partial MPA Request or Reply Frame can result in holding
a TCP connection open during a portion of connection establishment
that is not typically visible to the application.

APIs, such as DAT and IT-API, that attempt to make connection 
establishment
transport neutral should be aware that the iWarp "Communication Manager"
needs to protect itself against this type of attack.

But otherwise I don't see a vulnerability. You either exchange MPA
Start Frames properly, and enable an iWarp connection, or you fail
to do so and the TCP connection is terminated. The only vulnerability
is that TCP resources may be tied up if whatever component is handling
the MPA Start Frame exchange fails to diagnose failures promptly.

But that is true of *any* TCP application.



-- 
Caitlin Bestler - [email protected] - http://asomi.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.