Monday, December 27, 2010

From the Linux kernel vulnerability perspective system security

C (B) — — — — > PSH AIP spoofing attacks using RPC server only dependent on the source IP address for security verification of characteristics, the attack is the most difficult to predict A difficulty of ISN. attack, but a greater chance of success.

C must accurately anticipate possible from A to B, and A look forward to what comes from B's response, this requires the attacker to Protocol itself is quite familiar with. At the same time need to understand that this kind of attack is not possible to complete in interactive mode, you must write the program to complete. Of course, in the prepare phase can be used to netxray tool such as protocol analysis. Summary by analyzing the above several vulnerabilities we can see that Linux is not perfect, there are a lot of room for improvement. Some vulnerabilities have a significant impact on the promotion and use of Linux, for example above the table conflict Linuxhash vulnerability because some manufacturers and firewall vendor IDS is based on the Linux kernel to develop your own product, if you still use the hash algorithm for Linux itself would be the impact of this vulnerability, an attacker could easily carry out DoS attacks. Because firewalls, IDS itself is a security product, if they are attacked they will make the user a great loss, so we need to keep track of these vulnerabilities, and by understanding their behavior to avoid system once again produce these types of vulnerabilities, through these types of vulnerabilities forecasting mining, allowing us to proactively defense against hackers.

No comments:

Post a Comment