Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 8 Aug 2001 16:56:39 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        John Jennings <my_pinup_girl@www.com>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: uptime values in kernel
Message-ID:  <20010808165638.A91680@xor.obsecurity.org>
In-Reply-To: <200108082246.PAA01726@mail19.bigmailbox.com>; from my_pinup_girl@www.com on Wed, Aug 08, 2001 at 03:46:48PM -0700
References:  <200108082246.PAA01726@mail19.bigmailbox.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--mP3DRpeJDSE+ciuQ
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Aug 08, 2001 at 03:46:48PM -0700, John Jennings wrote:
> Hello all:
>=20
> As stated on this page:
>=20
> http://uptime.netcraft.com/up/accuracy.html#whichos
>=20
> FreeBSD 3.0 and later 'default configuration' does not supply
> accurate uptime statistics to Netcraft so that they may plot a
> graph.  What is meant by 'default configuration'?  I got a few
> pointers on DALnet #freebsd.  They said that I am attempting to
> 'change the kernel so that it displays the correct uptime.'
>
> I do believe this is a matter of little importance; but, for
> knowledge sake, I would like some information on how to reach my
> desired goal.  Does it involve compiling a new kernel or simply
> changing an obscure configuration file?

The current implementation of RFC 1323 TCP extensions leaks the system
uptime to remote systems.  RFC 1323 was disabled in 3.0 because it
causes certain ancient (really ancient) hardware to break, but it's
recently been re-enabled because a number of other OSes didn't bother
about breaking that hardware, and so it's basically safe now.  You can
enable it in /etc/rc.conf by setting tcp_extensions=3D"YES".

Note that leaking of system uptime has indirect security implications:
there have been a number of attacks in the past which rely on, or are
made much easier by, a precise knowledge of the system uptime.

Kris


--mP3DRpeJDSE+ciuQ
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE7cdG1Wry0BWjoQKURAnWzAJsFUdmpHYeRXbuY/t5rpLtzqb1d5gCfRyIS
MFYsQ4QFFppqaVrTWg592Mk=
=lgSM
-----END PGP SIGNATURE-----

--mP3DRpeJDSE+ciuQ--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010808165638.A91680>