Interesting People mailing list archives

IP: Re: [ "fun" to read djf] Gibson stops 13-year-old DOS `terrorist,' but says W2K and XP will fail and fall


From: David Farber <dave () farber net>
Date: Fri, 01 Jun 2001 12:32:48 -0400



To: farber () cis upenn edu, ip-sub-1 () majordomo pobox com
Subject: Re: IP: [ "fun" to read djf]  Gibson stops 13-year-old DOS
  `terrorist,' but says W2K and XP will fail and fall
Cc: bobf () Frankston com

This is a great story, and instructive.  But the one problem I have is 
with Steve's simplistic analysis that Windows XP and Windows 2000 are 
major increases in vulnerability *because* they allow spoofed IP datagrams 
to be *sent*.

Linux and other machines routinely allow such things.  And for a (pretty 
good) reason that applies also to Windows machines - if a machine is to 
act as a router, it *must* be able to generate a source IP address 
different than its own.  Linux, Windows XP and Windows 2000 machines do 
act as routers - the NAT gateway and RRAS facilities are low cost, 
software only routers that are good values for those who have PCs 
available to run them.

The real problem causing today's DDOS attacks is that these systems 
(Windows and Linux) are so vulnerable to Trojans and other attacks that 
allow the distributed deployment of agents/Zombies.  The fix has been 
obvious for 20 years - good strong crypto-based end-to-end security, 
certificates, and sandboxing of downloaded applications that you want to 
try but don't fully trust.  We have the law enforcement community to thank 
for blocking end-to-end security and authentication, and we have the OS 
designers to blame for not developing good sandboxing virtual machine 
capabilities (since the hardware has supported VMs for a long time). (and 
Outlook's own sandboxing options are insufficient).



For archives see: http://www.interesting-people.org/


Current thread: