[ Home | Liste | F.A.Q. | Risorse | Cerca... ]


[ Data: precedente | successivo | indice ] [ Argomento: precedente | successivo | indice ]


Archivio: Settembre 2004 ml@sikurezza.org
Soggetto: [ml] Novità del simpatico XP SP2
Mittente: Lonely Wolf
Data: Fri, 10 Sep 2004 12:53:29 +0200 (CEST)
Su bugtraq è da un po'che se parla :)
cmq poco fa ho trovato questo e lo ritengo interessante:

http://www.microsoft.com/downloads/details.aspx?FamilyID=7bd948d7-b791-40b6-8364-685b84158c78&DisplayLang=en


"This document focuses on the changes in Windows XP Service Pack 2 and its
implications for developers. Examples and details are provided for several
of the technologies that are experiencing the biggest changes. Future
versions of this document will cover all new and changed technologies"

Ad esempio...boh questo

"
....
Restricted traffic over raw sockets

Detailed description
A very small number of Windows applications make use of raw IP sockets,
which provide an industry-standard way for applications to create TCP/IP
packets with fewer integrity and security checks by the TCP/IP stack. The
Windows implementation of TCP/IP still supports receiving traffic on raw IP
sockets. However, the ability to send traffic over raw sockets has been
restricted in two ways:
·	TCP data cannot be sent over raw sockets.
·	UDP datagrams with invalid source addresses cannot be sent over raw
sockets. The IP source address for any outgoing UDP datagram must exist on a
network interface or the datagram is dropped. 

Why is this change important? What threats does it help mitigate?

This change limits the ability of malicious code to create distributed
denial-of-service attacks and limits the ability to send spoofed packets,
which are TCP/IP packets with a forged source IP address...."

Saluti 
Lonely Wolf 
 --
 Email.it, the professional e-mail, gratis per te: http://www.email.it/f
 
 Sponsor:
 18 Bottiglie di eccellenti vini Giordano + 7 specialità alimentari +
1 carrello dispensa "Servant" in legno massiccio Tutto a metà prezzo!

 Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=2621&d=20040910






[ Home | Liste | F.A.Q. | Risorse | Cerca... ]

www.sikurezza.org - Italian Security Mailing List
(c) 1999-2005