<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Sequence prediction in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879223#M100516</link>
    <description>Hi:&lt;BR /&gt;&lt;BR /&gt;For 11.0, see PHNE_21767.  For 11.11, see PHNE_27063.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
    <pubDate>Fri, 10 Jan 2003 16:05:20 GMT</pubDate>
    <dc:creator>James R. Ferguson</dc:creator>
    <dc:date>2003-01-10T16:05:20Z</dc:date>
    <item>
      <title>TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879222#M100515</link>
      <description>High,&lt;BR /&gt;&lt;BR /&gt;What patches do I need to stop the TCP sequence on my servers being predictable? This is a security vulnerability. I tried a search, but I can't find the exact patch the fixes the issue.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.</description>
      <pubDate>Fri, 10 Jan 2003 15:58:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879222#M100515</guid>
      <dc:creator>David Connolly</dc:creator>
      <dc:date>2003-01-10T15:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879223#M100516</link>
      <description>Hi:&lt;BR /&gt;&lt;BR /&gt;For 11.0, see PHNE_21767.  For 11.11, see PHNE_27063.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Fri, 10 Jan 2003 16:05:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879223#M100516</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2003-01-10T16:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879224#M100517</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Try looking at PHNE_26771.  Here is a snippet from the patch description [fixed in patch PHNE_26445 which is superseded by PHNE_26771]:&lt;BR /&gt;&lt;BR /&gt;( SR number:  8606213513 ; Defect:  JAGad82705 )&lt;BR /&gt; Systems relying on random increments for choosing less&lt;BR /&gt; predictable TCP ISN values, are still vulnerable to&lt;BR /&gt; statistical attacks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Also, here is a link to a great web site called "Strange Attractors and TCP/IP Sequence Number Analysis - One Year Later ".  This site analyzes the TCP/IP sequence numbers for a lot of different operating systems and plots the results as 3D plots.  Great stuff!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://lcamtuf.coredump.cx/newtcp/" target="_blank"&gt;http://lcamtuf.coredump.cx/newtcp/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;JP&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Jan 2003 16:06:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879224#M100517</guid>
      <dc:creator>John Poff</dc:creator>
      <dc:date>2003-01-10T16:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879225#M100518</link>
      <description>TCP sequence numbers _have_ to be predictable. I suspect you mean TCP _initial_ sequence numbers - ie the sequence number that TCP uses at the beginning of a connection.&lt;BR /&gt;&lt;BR /&gt;There was a recent security bulletin about RFC 1918 support in HP-UX. PHNE_26771 as mentioned by John is the 11.0 patch mentioned in that.&lt;BR /&gt;&lt;BR /&gt;If you are concerned about system security, it would be a really good idea to sign-up for the security notifications:&lt;BR /&gt;&lt;BR /&gt; C. To subscribe to automatically receive future NEW HP Security&lt;BR /&gt;    Bulletins from the HP IT Resource Center via electronic&lt;BR /&gt;    mail, do the following:&lt;BR /&gt;&lt;BR /&gt;    Use your browser to get to the HP IT Resource Center page&lt;BR /&gt;    at:&lt;BR /&gt;&lt;BR /&gt;       &lt;A href="http://itrc.hp.com" target="_blank"&gt;http://itrc.hp.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;    Use the 'Login' tab at the left side of the screen to login&lt;BR /&gt;    using your ID and password.  Use your existing login or the&lt;BR /&gt;    "Register" button at the left to create a login, in order to&lt;BR /&gt;    gain access to many areas of the ITRC.  Remember to save the&lt;BR /&gt;    User ID assigned to you, and your password.&lt;BR /&gt;&lt;BR /&gt;    In the left most frame select "Maintenance and Support".&lt;BR /&gt;&lt;BR /&gt;    Under the "Notifications" section (near the bottom of&lt;BR /&gt;    the page), select "Support Information Digests".&lt;BR /&gt;&lt;BR /&gt;    To -subscribe- to future HP Security Bulletins or other&lt;BR /&gt;    Technical Digests, click the check box (in the left column)&lt;BR /&gt;    for the appropriate digest and then click the "Update&lt;BR /&gt;    Subscriptions" button at the bottom of the page.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Jan 2003 18:55:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879225#M100518</guid>
      <dc:creator>rick jones</dc:creator>
      <dc:date>2003-01-13T18:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879226#M100519</link>
      <description>Please note that, while PHNE_21767 and PHNE_27063 will increase ISN randomness, this functionality is not turned on in the patch by default.  This is because (as I understand it) the increased overhead required by the computations can reduce transport efficiency, so HP included the functionality but didn't want to reduce performance for those folks who don't need the extra ISN randomness.&lt;BR /&gt;&lt;BR /&gt;Here's the relevant text, cut from the patch text for PHNE_27063:&lt;BR /&gt;&lt;BR /&gt;Defect Description:&lt;BR /&gt; The RFC 1948 ("Defending against sequence&lt;BR /&gt; number attacks") is not supported.&lt;BR /&gt;&lt;BR /&gt; Resolution:&lt;BR /&gt; The RFC 1948 is now implemented for computing&lt;BR /&gt; TCP ISN values. By default, the support for&lt;BR /&gt; RFC 1948 is turned off. It can be turned on by&lt;BR /&gt; using the ndd variable, tcp_isn_passphrase&lt;BR /&gt; &lt;SECRET passphrase=""&gt;. The secret passphrase can be&lt;BR /&gt; of any length, but only the first 32 characters&lt;BR /&gt; will be retained. The passphrase, once set, should&lt;BR /&gt; not be changed, except possibly at reboot.&lt;BR /&gt; For example:&lt;BR /&gt; ndd -set /dev/tcp tcp_isn_passphrase "rfc 1948"&lt;BR /&gt; will turn on the support for RFC 1948.&lt;BR /&gt; ( SR:8606213579 CR:JAGad82771 )&lt;BR /&gt;&lt;BR /&gt;I have asked for this info to be added to the special instructions for these patches, but there has been no change so far...&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Dave&lt;/SECRET&gt;</description>
      <pubDate>Mon, 13 Jan 2003 19:13:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879226#M100519</guid>
      <dc:creator>Dave Unverhau_1</dc:creator>
      <dc:date>2003-01-13T19:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Sequence prediction</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879227#M100520</link>
      <description>Thanks all,&lt;BR /&gt;&lt;BR /&gt;That more than answers my question.</description>
      <pubDate>Tue, 14 Jan 2003 08:30:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tcp-sequence-prediction/m-p/2879227#M100520</guid>
      <dc:creator>David Connolly</dc:creator>
      <dc:date>2003-01-14T08:30:20Z</dc:date>
    </item>
  </channel>
</rss>

