Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's very easy to do in NAT'ed environments and the Linux kernel doesn't implement the suggestion of the RFC draft to include timestamps too.

An attacker who doesn't want to do a MITM attack because that might be noticed can set up sessions to all kinds of servers outside the NAT which support TFO. Then all these TFO cookies are used in spoofed SYN packets with the source IP being set to the host behind the NAT that the attacker wants to flood. Easy enough.



Yep.

Of course, some will argue that if the attacker is inside your NAT, you're already pwned.

I don't think that's a very good principle for the security design of internet protocols.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: