Sponsored Content
Operating Systems Solaris Sun Fire E2900 crashed. Help analyze explorer Post 302368128 by incredible on Wednesday 4th of November 2009 07:04:45 AM
Old 11-04-2009
In this kind of panic and to find the root cause, it is not so straight forward. Need to analyse the crashdump.

Document Audience: PUBLIC
Document ID: 200864
Title: Security Vulnerability in the TCP Implementation of Solaris Systems May Allow a Denial of Service When Accepting New Connections While Undergoing a TCP "SYN Flood" Attack
Copyright Notice: Copyright ? 2008 Sun Microsystems, Inc. All Rights Reserved
Update Date: Wed Jul 30 00:00:00 MDT 2008

Solution Type Sun Alert

Solution 200864 : Security Vulnerability in the TCP Implementation of Solaris Systems May Allow a Denial of Service When Accepting New Connections While Undergoing a TCP "SYN Flood" Attack
Related Categories
Home>Content>Sun Alert Criteria Categories>Security

Home>Content>Sun Alert Release Phase>Resolved



Bug ID
6402737


Product
Solaris 8 Operating System, Solaris 9 Operating System, Solaris 10 Operating System


Date of Resolved Release
06-May-2008


SA Document Body
Security Vulnerability in the TCP Implementation of Solaris Systems May Allow a Denial of Service When Accepting New Connections While Undergoing a TCP "SYN Flood" Attack

1. Impact


A security vulnerability in the TCP implementation of Solaris 8, 9 and 10 may allow a remote unprivileged user to cause a Solaris system which is undergoing a "TCP SYN" flood condition to be slow to accept new network connections. Such network connections may time out without establishing a connection. This would lead to a Denial of Service (DoS) to the network services provided by that system. In addition, a uniprocessor system may also experience overall slowdown due to high CPU usage, resulting in a Denial of Service to the system as a whole.

2. Contributing Factors


This issue can occur in the following releases:

SPARC Platform
Solaris 8 without patch 116965-33
Solaris 9 without patch 114344-35
Solaris 10 without patch 119998-01

x86 Platform
Solaris 8 without patch 116966-32
Solaris 9 without patch 119435-23
Solaris 10 without patch 119999-01

Note: This issue affects hosts which have a value for the ndd(1M) tunable 'tcp_conn_req_max_q0' which is considerably higher than the default value of 1024. The higher the value, the greater the impact of this issue if it is exploited on a host. While a value close to or less than 1024 does not make the system immune to a Denial of Service, it decreases the impact of a DoS on the system.

To determine the value of the 'tcp_conn_req_max_q0' tunable, the following command can be used:
$ ndd -get /dev/tcp tcp_conn_req_max_q0
1024

3. Symptoms


If this issue is exploited, the following message may be seen on the console:
WARNING: High TCP connect timeout rate!
System (port <port number>) may be under a SYN flood attack

4. Workaround


To work around the described issue, make sure the value of the ndd(1M) tunable 'tcp_conn_req_max_q0' for TCP is not much higher than the default of 1024, using commands such as the following:
$ ndd -get /dev/tcp tcp_conn_req_max_q0
4000
$ ndd -set /dev/tcp tcp_conn_req_max_q0 1024
$ ndd -get /dev/tcp tcp_conn_req_max_q0
1024

5. Resolution


This issue is addressed in the following releases:

SPARC Platform
Solaris 8 with patch116965-33 or later
Solaris 9 with patch 114344-35 or later
Solaris 10 with patch 119998-01 or later

x86 Platform
Solaris 8 with patch 116966-32 or later
Solaris 9 with patch 119435-23 or later
Solaris 10 with patch 119999-01 or later
Note: There are additional Solaris 8 and 9 patches which list 6402737 in their README, however these patches are not required to address the issue described in this Sun Alert. These additional patches deliver an updated kernel debugger (kadb(1M)). The patch-IDs are:

SPARC Platform
Solaris 8 patch 117350-54 or later
Solaris 9 patch 122300-25 or later
x86 Platform
Solaris 8 patch 117351-54 or later
Solaris 9 patch 122301-25 or later
 

9 More Discussions You Might Find Interesting

1. UNIX for Advanced & Expert Users

Sun Fire v1280 is crashing

I still haven't got an answer to this question... Excerpt from My SysAd Blog A colleague of mine is having a problem with a Sun Fire v1280 server crashing. He tried Googling for the error message in red but hasn't found anything yet. Your insights would be greatly appreciated. "cannot... (2 Replies)
Discussion started by: esofthub
2 Replies

2. UNIX for Dummies Questions & Answers

Sun Fire 280R

Hello all, I'm lost and can't figure this problem out. I have a Sun fire 280R running Solaris 8. Everything was working great. I have one drive in bay 1(not 0). But when I reboot the system it trys to open files in /dev/rdsk/c1t1d0s0. Should it have been opeing /dev/rdsk/c1t0d0s0, the... (4 Replies)
Discussion started by: larryase
4 Replies

3. Solaris

Sun Fire V1280 / E2900 / Netra 1280

Hello, I'm trying to fix this server System Board (CPU/Memory Unit). The error indicates that its missing 3.3VDC. So far all the fuses and caps have been checked. I new at this type of machine, need help for idea on this system. Thank you in advance. Vu (0 Replies)
Discussion started by: vhtran
0 Replies

4. Solaris

Sun Machine Crashed

During system startup the following warnings are appear. Warning: /pci@8, 700000/scsi@6, 1 (g1m1) Connected command timeout for target 9.0 Warning: /pci@8, 700000/scsi@6, 1 (g1m1) Target 9 reducing sync, transfer rate Warning: /pci@8, 700000/scsi@6, 1... (5 Replies)
Discussion started by: tabreaz
5 Replies

5. Solaris

Sun Fire 280R Sun Solaris CRT/Monitor requirements

I am new to Sun. I brought Sun Fire 280R to practice UNIX. What are the requirements for the monitor/CRT? Will it burn out old non-Sun CRTs? Does it need LCD monitor? Thanks. (3 Replies)
Discussion started by: bramptonmt
3 Replies

6. Solaris

Config reader module in Sun MC Agent not work in E2900

Hi men, Have you ever meet this error ? I install full Sun MC 4.0 packages (+ Add ons) exception of Sun Midrange Platform Administration because i don't know how to configure it Then all other servers are ok, only E2900 servers have Config reader module error: Data Acquisition error I... (12 Replies)
Discussion started by: tien86
12 Replies

7. Solaris

Question for Sun explorer

I am running Sun Explorer to collect data, but /proc is very big in size so it is takin time to get completed. (Running from past 3 hours). I ran --> /opt/SUNWexplo/bin/explorer -w all,zones root@tsrim03:/# ps -ef | grep -i explo root 27623 6539 0 06:28:59 pts/1 0:03 ksh -p... (1 Reply)
Discussion started by: solaris_1977
1 Replies

8. Solaris

How-to find SerialNumber Sun E2900

several newbie questions: > how-to find serialnumber for Sun E2900 prtdiag -v does not show chassis serial number > LOM is not connectable . Are there any tools to get automatically Serial numbers for HW. Thanks ! (7 Replies)
Discussion started by: magedfawzy
7 Replies

9. Solaris

Sun fire x2270

Hello, I have purchaced an old SUn fire x2270 server . I wanted to make ILOM upgrade to the latest version of software : ILOM 3.0.9.18.a r126592 BIOS vers. 2.09 Server 2.2.3 (10-Aug-2018) Because my version is very outdated. But i can't download the updatebecause it's require... (4 Replies)
Discussion started by: LouisLakoute
4 Replies
All times are GMT -4. The time now is 11:06 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy