Bugtraq mailing list archives
Re: TCP Timestamping and Remotely gathering uptime information
From: Theo de Raadt <deraadt () CVS OPENBSD ORG>
Date: Mon, 19 Mar 2001 13:18:43 -0700
Darren Reed said:Why do you think all timestamps should not reveal uptime information ?Well, not to speak on Bret's behalf per se, but personally, I've seen plenty of software (the quality of which may be in question) that uses uptime (or clock-ticks-since-boot, whatever) for a variety of things, albeit ususally trivial.
Lots of such things exist. One example is RPC, which used to generate it's initial XID (which are subsequently incremented per transaction) from tv.tv_sec ^ tv.tv_usec ^ getpid(). On systems with predictable boot sequences, predictable pids, and known boot time, it is possible to figure out the window of XID usage, and spoof replies. Other such thigns do exist, get discovered, etc etc etc, and fixed on their own. However, ... it's nice to fix problems by accident.
Current thread:
- Re: TCP Timestamping and Remotely gathering uptime information, (continued)
- Re: TCP Timestamping and Remotely gathering uptime information Valdis Kletnieks (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information Saint skullY the Dazed (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information arivanov (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information Stephen White (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information bert hubert (Mar 20)
- Remote fingerprinting/uptime (was Re: TCP Timestamping ...) Darren Reed (Mar 20)
- Re: Remote fingerprinting/uptime (was Re: TCP Timestamping ...) Jason R Thorpe (Mar 22)
- Re: TCP Timestamping and Remotely gathering uptime information Chris Tobkin (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information Ted U (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information Matt Lewis (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information Theo de Raadt (Mar 20)
- Re: TCP Timestamping and Remotely gathering uptime information Darren Reed (Mar 19)
- Re: TCP Timestamping and Remotely gathering uptime information van der Kooij, Hugo (Mar 20)