Vulnerability Development mailing list archives

TCP on multicast (Solaris)


From: MA <mixalhs () noos fr>
Date: Sun, 26 Oct 2003 15:56:06 +0100

When a Solaris box receives an ACK packet from a multicast address
(224/4), it answers with a RST. This was described three years ago as
the "spank" attack by Tim Yardley:
http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00416.html
http://www.securityfocus.com/archive/1/43438/2000-01-19/2000-01-25/2

This paper contains several errors, and I am not sure that this is
really dangerous. Linux ignores TCP on multicast. Should Sun fix this?


Current thread: