
[ Home | Liste | F.A.Q. |
Risorse | Cerca... ]
Archivio: Settembre 2004 ml@sikurezza.org Soggetto: [ml] Novità del simpatico XP SP2 Mittente: Lonely Wolf Data: Fri, 10 Sep 2004 12:53:29 +0200 (CEST)
Su bugtraq è da un po'che se parla :) cmq poco fa ho trovato questo e lo ritengo interessante: http://www.microsoft.com/downloads/details.aspx?FamilyID=7bd948d7-b791-40b6-8364-685b84158c78&DisplayLang=en "This document focuses on the changes in Windows XP Service Pack 2 and its implications for developers. Examples and details are provided for several of the technologies that are experiencing the biggest changes. Future versions of this document will cover all new and changed technologies" Ad esempio...boh questo " .... Restricted traffic over raw sockets Detailed description A very small number of Windows applications make use of raw IP sockets, which provide an industry-standard way for applications to create TCP/IP packets with fewer integrity and security checks by the TCP/IP stack. The Windows implementation of TCP/IP still supports receiving traffic on raw IP sockets. However, the ability to send traffic over raw sockets has been restricted in two ways: · TCP data cannot be sent over raw sockets. · UDP datagrams with invalid source addresses cannot be sent over raw sockets. The IP source address for any outgoing UDP datagram must exist on a network interface or the datagram is dropped. Why is this change important? What threats does it help mitigate? This change limits the ability of malicious code to create distributed denial-of-service attacks and limits the ability to send spoofed packets, which are TCP/IP packets with a forged source IP address...." Saluti Lonely Wolf -- Email.it, the professional e-mail, gratis per te: http://www.email.it/f Sponsor: 18 Bottiglie di eccellenti vini Giordano + 7 specialità alimentari + 1 carrello dispensa "Servant" in legno massiccio Tutto a metà prezzo! Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=2621&d=20040910
[ Home | Liste | F.A.Q. |
Risorse | Cerca... ]
www.sikurezza.org - Italian Security Mailing List
(c) 1999-2005