October 11, 2008
Home
About
Submit Press Release
PR Firms
Editors/Journalists
Search Archives
 
News Releases by Category  
News by Country  
News by MSA  
All News for Today  
Browse News by Day  
News by Trackbacks  
All Press Releases for April 23, 2004 Subscribe to this News Feed  
 

InterNiche Technologies Posts Fix for Critical TCP/IP Denial of Service Scenario

InterNiche Technologies, Inc., a major supplier of Internet and network security protocols stacks used worldwide by network devices and embedded applications OEMs, today announced that they have updated their NicheStack and NicheLite stacks to address the TCP Reset (RST) and SYN Attack vulnerabilities that were disclosed today by the United Kingdoms National Infrastructure and Security Co-Ordination Centre. The use and effect of spoofed" RST (Reset) and SYN packets on the TCP/IP Internet communications protocol was detailed today in NISCC Vulnerability Advisory # 236929 and in a US Department of Homeland Security alert. If exploited, these vulnerabilities could potentially allow a Denial of Service (DoS) attack on any TCP/IP session, forcing a premature termination. Any network service or application that relies on TCP/IP could be impacted.

SAN JOSE, CA (PRWEB) April 23, 2004 -– InterNiche Technologies, Inc., a major supplier of Internet and network security protocols stacks used worldwide by network devices and embedded applications OEMs, today announced that they have updated their NicheStack and NicheLite stacks to address the TCP Reset (RST) and SYN Attack vulnerabilities that were disclosed today by the United Kingdoms National Infrastructure and Security Co-Ordination Centre. The use and effect of "spoofed" RST (Reset) and SYN packets on the TCP/IP Internet communications protocol was detailed today in NISCC Vulnerability Advisory # 236929 and in a US Department of Homeland Security alert. If exploited, these vulnerabilities could potentially allow a Denial of Service (DoS) attack on any TCP/IP session, forcing a premature termination. Any network service or application that relies on TCP/IP could be impacted.

"InterNiche has been working with the NISCC since first alerted to this vulnerability and on April 8th we informed NISCC that we had examined the scenario, had tested a patch and posted an updated version of our NicheStack IPv4, NicheStack IPv4/IPv6 Dual, and our NicheLite protocol stacks," said Brian Ramsey, Vice President of Marketing at InterNiche. "Embedded applications can be further protected with our IP Security (IPSec) security toolkits, which encrypts information at the network layer completely obscuring the 4-tuple TCP address and port information. IPSec provides authentication and other security functions that protect against spoofing and replay."

The vulnerability identified by researcher, Paul Watson, in his paper, Slipping In The Window: TCP Reset Attacks", to be presented this week at the CanSecWest2004 security conference identified a method of "spoofing" TCP RST or SYN packets making TCP Reset Attacks feasible.

Systems and services with persistent TCP/IP connections and relatively easy-to-guess address and port numbers are the most vulnerable targets for this form of DoS, or a Distributed DoS attack if launched from multiple cooperating machines. Border Gateway Protocol (BGP) routers, Domain Name Servers (DNS) and well-know e-commerce sites were identified as potentially affected by this vulnerability.

Availability
InterNiche Technologies has updated its NicheStack v2.0 and NicheLite v2.0 TCP/IP protocol stack products to handle the scenarios described in NISCC Vulnerability Notice #236929. The patch is available to all InterNiche customers in accordance with the terms of their current support agreements.

About InterNiche
InterNiche Technologies has been developing and licensing networking management and configuration software for embedded systems since 1989. Hundreds of thousands of products depend on InterNiche software as part of their core functionality. Customers include companies such as 3COM, Ericsson, Intel, Hewlett Packard, Nortel Networks, Raytheon, Samsung, Siemens, and many more.

For more information please contact sales@iniche.com or visit InterNiche on the web at www.iniche.com.
###


See the original story at: http://www.prweb.com/releases/2004/04/prweb120459.htm
Email this story to a colleague
Printer Friendly Version
Bookmark with del.icio.us
Bookmark with Y!MyWeb
Submit to Digg
Brian Ramsey
INTERNICHE TECHNOLOGIES, INC.
+1 (408) 257-8014
Email us Here

There are no multimedia files attached to this release. If this is your release you may add images or other multimedia files through your login.

If you have any questions regarding information in these press releases please contact the company listed in the press release. Please do not contact PRWeb. We will be unable to assist you with your inquiry. PRWeb disclaims any content contained in these release. Our complete disclaimer appears here.
 
Disclaimer: If you have any questions regarding information in these press releases please contact the company listed in the press release.
Please do not contact PRWeb®. We will be unable to assist you with your inquiry.
PRWeb® disclaims any content contained in these releases. Our complete disclaimer appears here.

© Copyright 1997-2007, Vocus PRW Holdings, LLC.
Vocus, PRWeb and Publicity Wire are trademarks or registered trademarks of Vocus, Inc. or Vocus PRW Holdings, LLC.

Terms of Service | Privacy Policy | Copyright