-
Notifications
You must be signed in to change notification settings - Fork 9
/
rcv-syn-last-ack-right-edge-insecure-ipv4.pkt
64 lines (61 loc) · 3.08 KB
/
rcv-syn-last-ack-right-edge-insecure-ipv4.pkt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
//
// Copyright (c) 2016 Michael Tuexen
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions
// are met:
// 1. Redistributions of source code must retain the above copyright
// notice, this list of conditions and the following disclaimer.
// 2. Redistributions in binary form must reproduce the above copyright
// notice, this list of conditions and the following disclaimer in the
// documentation and/or other materials provided with the distribution.
//
// THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
// ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
// IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
// ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
// FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
// DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
// OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
// HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
// LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
// OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
// SUCH DAMAGE.
//
// Ensure that the reception of a TCP SYN with SEG.SEQ = RCV.NXT + RCV.WND - 1
// in the LAST-ACK state destroys the TCP connection.
--ip_version=ipv4
--tolerance_usecs=75000
// Ensure that all relevant sysctl variables have their default values.
0.00 `sysctl -w net.inet.tcp.rfc1323=1`
+0.00 `sysctl -w net.inet.tcp.sack.enable=1`
+0.00 `sysctl -w net.inet.tcp.ecn.enable=2`
+0.00 `sysctl -w kern.ipc.maxsockbuf=2097152`
+0.00 `sysctl -w net.inet.tcp.recvspace=65536`
+0.00 `sysctl -w net.inet.tcp.sendspace=32768`
// Flush host cache.
+0.00 `sysctl -w net.inet.tcp.hostcache.purgenow=1`
// Ensure that the relevant sysctl variables have their value.
+0.00 `sysctl -w net.inet.tcp.insecure_syn=1`
// Create a TCP socket in LAST-ACK state
+0.00 socket(..., SOCK_STREAM, IPPROTO_TCP) = 3
+0.00 fcntl(3, F_GETFL) = 0x02 (flags O_RDWR)
+0.00 fcntl(3, F_SETFL, O_RDWR | O_NONBLOCK) = 0
+0.00 getsockopt(3, SOL_SOCKET, SO_RCVBUF, [65536], [4]) = 0
+0.00 connect(3, ..., ...) = -1 EINPROGRESS (Operation now in progress)
+0.00 > S 0:0(0) win 65535 <mss 1460,nop,wscale 6,sackOK,TS val 100 ecr 0>
+0.10 < S. 0:0(0) ack 1 win 32767 <mss 1460,sackOK,eol,eol>
+0.00 > . 1:1(0) ack 1 win 65535
// Now the recv buffer is 65770, since it is rounded up to a multiple of the MSS.
+0.00 getsockopt(3, SOL_SOCKET, SO_RCVBUF, [65700], [4]) = 0
+0.10 < F. 1:1(0) ack 1 win 32767
+0.00 > . 1:1(0) ack 2 win 65535
+0.00 shutdown(3, SHUT_WR) = 0
+0.00 > F. 1:1(0) ack 2 win 65535
// Now the connection is in LAST-ACK
+0.10 < S 65701:65701(0) win 32767 <mss 1460,sackOK,eol,eol>
+0.00 > R. 2:2(0) ack 2 win 0
+0.00 getsockopt(3, SOL_SOCKET, SO_ERROR, [ECONNRESET], [4]) = 0
+0.00 close(3) = 0
+0.00 `sysctl -w net.inet.tcp.insecure_syn=0`