- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Non-random ip id's
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2003 03:50 PM
тАО11-16-2003 03:50 PM
value of the ip_id field of the ip packets sent by this host.
Anyone suggest how we can cause random values for ip-ids in ip packets to be the norm?
We are running ux11.0 op system.
thanks
Maria
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-16-2003 07:17 PM
тАО11-16-2003 07:17 PM
Re: Non-random ip id's
Regards,
Tony.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2003 12:15 AM
тАО11-18-2003 12:15 AM
Solutionhttp://www1.itrc.hp.com/service/cki/secBullArchive.do
Check out bulletin 205. You'l want at least patch PHNE_26771, which then gives you a choice of "HP randomization" or RFC1948 randomization.
-Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2003 12:59 AM
тАО11-18-2003 12:59 AM
Re: Non-random ip id's
Results for HP from the second study can be seen here:
http://lcamtuf.coredump.cx/newtcp/#hpux
Apply the patch and follow the instructions to activate the change and you should be all set.
mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2003 05:53 AM
тАО11-18-2003 05:53 AM
Re: Non-random ip id's
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-18-2003 05:59 AM
тАО11-18-2003 05:59 AM
Re: Non-random ip id's
see here for one man's take on the risks:
http://lcamtuf.coredump.cx/newtcp/#risks
mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-19-2003 11:29 AM
тАО11-19-2003 11:29 AM
Re: Non-random ip id's
thanks for the pointer - perhaps I dind't read far enough, but the first bit there seemed to be concerned only with TCP sequence numbers and spoofed IP addresses and didn't say anything about IP datagram IDs, which to the best of my knowledge are used only in IP fragment reassembly.
i suppose that one might argue that an attacker might then be able to "insert" replacement IP datagram fragments in the middle of a fragmented IP datagram, but that seems very remote as the chances of being able to put something useful there that still passes the TCP (which avoids fragmentation) or UDP checksum seems remote at best.