Beck, Aaron wrote: [snip, line breaks woulda been nice, BTW]
However, most of the other protocols have -some- form of integrity checking - whether its on the data itself (as in DNS Zone Transfers), or higher up in the protocol stack (such as SSH and TCP Encapsulation of IPSEC).
Whatever you do at the application layer doesn't change this vulnerability. SSH is just as vulnerable as telnet or FTP. The attacker can reset the TCP connection, and therefore the SSH session riding on TCP, just as easily.
IPsec, either AH or ESP, do virtually eliminate any possibility of the attack, but IPsec takes place "under" TCP. IPsec protects or "encapsulates" TCP. But something like "TCP encapsulation of IPsec" _would_ be vulnerable to being reset. How disruptive this is to a kludge like IPsec over TCP depends on just how ugly the hackish implementation is.
Another way to protect TCP is with the MD5 Signature TCP option, RFC2385. This is a modification to TCP itself. But that is not widely deployed anywhere accept in BGP speaking routers. -- Crist J. Clark [EMAIL PROTECTED] Globalstar Communications (408) 933-4387
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
