Linux Distributions Vulnerable to Cyber-Attacks: Report

Advertisement
By Indo-Asian News Service | Updated: 10 August 2016 18:21 IST
Researchers from University of California-Riverside have identified a weakness in the Transmission Control Protocol (TCP) of all Linux operating systems that enables attackers to remotely hijack users' internet communications.

Such a weakness could be used to launch targeted attacks that track users' online activity, forcibly terminate a communication, hijack a conversation between hosts or degrade the privacy guarantee by anonymity networks such as Tor.

To transfer information from one source to another, Linux and other operating systems use the Transmission Control Protocol (TCP) to package and send data, and the Internet Protocol (IP) to ensure the information gets to the correct destination.

When two people communicate by email, TCP assembles their message into a series of data packets, identified by unique sequence numbers, that are transmitted, received, and reassembled into the original message.

Advertisement

Those TCP sequence numbers are useful to attackers, but with almost four billion possible sequences, it is essentially impossible to identify the sequence number associated with any particular communication by chance.

Advertisement

The researchers led by Yue Cao, computer science graduate student, identified a subtle flaw in the Linux software that enables attackers to infer the TCP sequence numbers associated with a particular connection with no more information than the IP address of the communicating parties.

This means that given any two arbitrary machines on the internet, a remote blind attacker without being able to eavesdrop on the communication, can track users' online activity, terminate connections with others and inject false material into their communications.

Advertisement

The weakness can allow attackers to degrade the privacy of anonymity networks, such as Tor, by forcing the connections to route through certain relays, the authors stated.

The attack is fast and reliable, happens in less than a minute and has a success rate of about 90 percent.

Advertisement

The researchers alerted Linux about the vulnerability which resulted in patches applied to the latest Linux version.

The study was set to be presented at the USENIX Security Symposium in Austin, Texas, this week.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Hijacking, Internet, Laptops, Linux, PC, Tor, Ubuntu
Advertisement

Related Stories

Popular Mobile Brands
  1. Gemini October Feature Drop Brings New Features to Veo 3.1, Canva, and More
  2. iQOO Neo 11: Launch Date, Expected Price, Design, Specifications, Features, and More
  3. Lazarus Now Streaming on Amazon Prime Video: What You Need to Know
  1. Baai Tuzyapayi OTT Release Date: When and Where to Watch Marathi Romantic Drama Online?
  2. Maxton Hall Season 2 OTT Release Date: When and Where to Watch it Online?
  3. Shakti Thirumagan Now Streaming on JioHotstar: Everything You Need to Know About Vijay Antony’s Political Thriller
  4. Semi-Transparent Solar Cells Break Records, Promise Energy-Generating Windows and Facades
  5. Chang’e-6 Lunar Samples Reveal Water-Rich Asteroid Fragments
  6. James Webb Telescope Uncovers the Turbulent Birth of the First Galaxies
  7. Troll 2 OTT Release Date: When and Where to Watch it Online?
  8. Baramulla OTT Release Date: When and Where to Watch Gripping Thriller Set in the Heart of Kashmir Online?
  9. Lazarus Now Streaming on Amazon Prime Video: What You Need to Know
  10. Gemini October Feature Drop Brings New Features to Veo 3.1, Gemini 2.5 Flash, Canvas, and More
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.