Live data from Hacker News

IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

samsclass.info

11–20 of 54 posts

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#11

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

I take it 12/11/12 is a December date, not the November one that it is by convention here... I missed that and assumed a month had been given, as screen grabs show November dates.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#14

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

I'm not defending the disclosure procedures but I think the author is under the impression that Apple is not going to care/respond and therefore not worth waiting X days before announcing publicly:

"The new version of the attack is powerful enough that I decided to formally notify Apple. I don't expect them to care much--Microsoft certainly didn't think this was important to them, and Windows is much more vulnerable."

Its also worth noting that while this vuln has a high availability impact it is also requires very specific network access, ie you can't run this from your cable modem and kill a random box on the internet.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#15

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#16

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

I take it 12/11/12 is a December date, not the November one that it is by convention here... I missed that and assumed a month had been given, as screen grabs show November dates.

Yeah - I deal with the UK often enough I had to double check the timeline to be sure:

  o First posted: 7:30 am 11-20-12 by Sam Bowne
  o Page reorganized with Contents section 11-30-12 10:36 am
  o New videos 4 and 5 added 12-5-12
  o BayThreat Videos added 12-8-12 11:19 pm
  o Attacks on the Mac OS X with simulated routers added 7:45 pm, 12-10-12.
  o Apple notified 12-11-12

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#17
post #3

Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.

Land? A single spoofed TCP SYN packet with identical src/dst addresses was enough to crash or at least impact many OSs.

http://www.physnet.uni-hamburg.de/physnet/security/vulnerabi...

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#20

In the video, he tested OS X, Windows XP, and Server 2012. OS X beachballed, XP went to 100% CPU, and Server 2012 panicked and rebooted. All three failed; this isn't just an Apple issue. Was Microsoft notified as well?

In my experience (and as this article suggests), Microsoft operating systems have always been really vulnerable to flooding, even over IPv4. Malformed UDP packets to port 53 (DNS) at about 20-30k packets/sec instantly would lock up a windows box and prevent it from successfully rebooting. This was one of the preferred methods for the wargames that were played for bandwidth over the shared housing network for Microsoft Research interns in China a few years back.
Post reply on HN