Live data from Hacker News

IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

samsclass.info

31–40 of 54 posts

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#31
post #22
post #9

Earlier quoted context omitted.

There is an active debate on whether immediate full disclosure is the right or the wrong response. In general until there is public disclosure, vendors do not feel motivated to fix problems. Unless you release details, people cannot verify that they are vulnerable. And if an exploit is already circulating among "the bad guys", then you're not doing that much damage by disclosing. In this case it looks like someone is…

That depends on the vendor. Some vendors are slow, some vendors are fast. It is wrong to say that no vendor even fixes bugs unless they are publicly disclosed, it is not what responsible disclosure means.

When I say "in general" that means not so for every vendor.

That said, Apple's track record on this topic is not exactly stellar.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#33
post #23
post #14

Earlier quoted context omitted.

I'm not defending the disclosure procedures but I think the author is under the impression that Apple is not going to care/respond and therefore not worth waiting X days before announcing publicly: "The new version of the attack is powerful enough that I decided to formally notify Apple. I don't expect them to care much--Microsoft certainly didn't think this was important to them, and Windows is much more vulnerable.…

To send router advertisement packets to a remote network (obviously spoofing the return address) shouldn't be very hard, but I don't know if firewalls or routers in between will refuse to forward the packet. Anyone want to perform a test with me?

Since this is a neighbour discovery mechanism, RAs/RSs are mandated to be link-local (either LL multicast when non solicited or LL unicast in reply to sollicitation), therefore the scope will kill routing. A router passing around such crafted RA/RS or a node not dropping such crafted RAs would be non-compliant and would just break the neighbour discovery mechanism anyway even without any form of attack as it does not make any sense.

Therefore the attack is bounded to the neighbour router(s).

From the RFC [0]

    Source Address
                     MUST be the link-local address assigned to the
                     interface from which this message is sent.
[0]: http://tools.ietf.org/html/rfc4861#page-19

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#34

In case someone is curious about the code, visit http://opensource.apple.com/source/xnu/xnu-2050.18.24/bsd/ne... and look for nd6_ra_input()

Reading that code I finally realise why Mac OS X doesn't correctly handle option 24 (alternate routes).

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#35
post #9

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

There is an active debate on whether immediate full disclosure is the right or the wrong response. In general until there is public disclosure, vendors do not feel motivated to fix problems. Unless you release details, people cannot verify that they are vulnerable. And if an exploit is already circulating among "the bad guys", then you're not doing that much damage by disclosing. In this case it looks like someone is…

I think vendors should have a policy for dealing with security vulnerabilities. The policy should say how much time they will take to fix it and how they will give credit those who found the issue.

If a vendor does not have such a policy or is found to have violated it, I would go for immediate full disclosure.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#36
post #29

Since this attack is based on Router Advertisements, you need to be on the same LAN to exploit it. It also does not apply if the LAN implements RA Guard (RFC6105).

http://tools.ietf.org/id/draft-gont-v6ops-ra-guard-evasion-0... , but maybe you're right about the LAN part.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#37
post #26
post #15

Earlier quoted context omitted.

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?

What else should a person put on their resume (beyond job experience) when applying for security roles? Patents? Education? Open Source Projects? I would think that CVE-IDs would certainly lend color, and probably credibility to the resume of someone applying for a security position, particularly if the CVE-ID (which has some amount of peer review) was associated with something interesting or relevant to the position being applied for.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#38

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

I take it 12/11/12 is a December date, not the November one that it is by convention here... I missed that and assumed a month had been given, as screen grabs show November dates.

I dream (awake!) of The World seeing that date, thinking something along the lines of "but hey, that's annoying, I'm not sure which date that refers to!" and then just adopting ISO 8601 immediately.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#39
post #24
post #15

Earlier quoted context omitted.

When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.

Unless there were an easy workaround which you could disclose only with disclosing the rest of the problem - yes, it was.

This assumes something that I don't believe is defendable: that bad people wanting to install keyloggers on these systems did not already have knowledge of this vulnerability (or, even simpler, that one would seriously believe that they would be unable to find this vulnerability without splicer having told them about it, as somehow he had unique knowledge of the system). Just because I don't have a way to protect myself from harm does not imply that I am somehow better off not knowing that people can harm me.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#40
post #29

Since this attack is based on Router Advertisements, you need to be on the same LAN to exploit it. It also does not apply if the LAN implements RA Guard (RFC6105).

http://www.youtube.com/watch?v=8Q8EFwKVKdA for some non-trivial but ingenious ways you can get to a LAN from the outside. (Then again if you're as useless as my ISP, leaving the telnet server on the DSL modem with a default password, listening on the WAN, you don't need to do anything fancy to exploit LANs)
Post reply on HN