Live data from Hacker News

IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

samsclass.info

21–30 of 54 posts

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#22
post #9

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

There is an active debate on whether immediate full disclosure is the right or the wrong response. In general until there is public disclosure, vendors do not feel motivated to fix problems. Unless you release details, people cannot verify that they are vulnerable. And if an exploit is already circulating among "the bad guys", then you're not doing that much damage by disclosing. In this case it looks like someone is…

That depends on the vendor. Some vendors are slow, some vendors are fast. It is wrong to say that no vendor even fixes bugs unless they are publicly disclosed, it is not what responsible disclosure means.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#23
post #14

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

I'm not defending the disclosure procedures but I think the author is under the impression that Apple is not going to care/respond and therefore not worth waiting X days before announcing publicly: "The new version of the attack is powerful enough that I decided to formally notify Apple. I don't expect them to care much--Microsoft certainly didn't think this was important to them, and Windows is much more vulnerable.…

To send router advertisement packets to a remote network (obviously spoofing the return address) shouldn't be very hard, but I don't know if firewalls or routers in between will refuse to forward the packet.

Anyone want to perform a test with me?

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#24
post #15

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

Unless there were an easy workaround which you could disclose only with disclosing the rest of the problem - yes, it was.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#26
post #15

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#27
post #3

Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.

Except, for this attack you have to be link-local (fe80 is local scope, and so are router advertisements). Realistically, for most server installs you're okay. For coffee shops with an open, insecure broadcast domain, not so much

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#28

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

If there's no reason to believe that the exploit is already being used in the wild, then I completely agree.

I also think that a good compromise would be to pass on the exploit information to some 3rd party, tasked with releasing full details at a certain date (or simply, the responsible release of the exploit). The focus of pressure would then shift from the researcher to this 3rd party, which would presumably have the means to resist the pressure.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#30
post #26
post #15

Earlier quoted context omitted.

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?

It helped land me a firmware development position at what was then a fortune 500 company.
Post reply on HN