cvs commit: src/sys/netinet in_pcb.c src/sys/netinet6 in6_pcb.c

Yar Tikhiy yar at FreeBSD.org
Wed Jul 28 06:03:08 PDT 2004


yar         2004-07-28 13:03:07 UTC

  FreeBSD src repository

  Modified files:
    sys/netinet          in_pcb.c 
    sys/netinet6         in6_pcb.c 
  Log:
  Disallow a particular kind of port theft described by the following scenario:
  
          Alice is too lazy to write a server application in PF-independent
          manner.  Therefore she knocks up the server using PF_INET6 only
          and allows the IPv6 socket to accept mapped IPv4 as well.  An evil
          hacker known on IRC as cheshire_cat has an account in the same
          system.  He starts a process listening on the same port as used
          by Alice's server, but in PF_INET.  As a consequence, cheshire_cat
          will distract all IPv4 traffic supposed to go to Alice's server.
  
  Such sort of port theft was initially enabled by copying the code that
  implemented the RFC 2553 semantics on IPv4/6 sockets (see inet6(4)) for
  the implied case of the same owner for both connections.  After this
  change, the above scenario will be impossible.  In the same setting,
  the user who attempts to start his server last will get EADDRINUSE.
  
  Of course, using IPv4 mapped to IPv6 leads to security complications
  in the first place, but there is no reason to make it even more unsafe.
  
  This change doesn't apply to KAME since it affects a FreeBSD-specific
  part of the code.  It doesn't modify the out-of-box behaviour of the
  TCP/IP stack either as long as mapping IPv4 to IPv6 is off by default.
  
  MFC after:      1 month
  
  Revision  Changes    Path
  1.152     +1 -10     src/sys/netinet/in_pcb.c
  1.57      +1 -5      src/sys/netinet6/in6_pcb.c


More information about the cvs-all mailing list