Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE

The Windows registry key EnableICMPTimestampRep=0 is silently ignored by tcpip.sys — Ipv4pHandleTimestampRequest generates ICMP Type 14 replies unconditionally regardless of the registry value. Ghidra static analysis of tcpip.sys 10.0.26100.8457 reveals a second RFC 792 violation: Receive and Transmit timestamps are written in little-endian byte order while the adjacent IP Timestamp Option handler correctly calls htonl() on the same value. Confirmed via pcap, netstat ICMP counters, and WinDbg kernel breakpoints. CVE-1999-0524 scope analysis and WFP mitigation rule included.

July 24, 2026 · 11 min · JM00NJ
Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE

AI Agent Security: Why Container Isolation & Linux RBAC Beat AI Firewalls | Kernel-Level Access Control

Governing an AI agent with another AI firewall creates the Quis Custodiet paradox: both systems are probabilistic and subject to prompt injection and data poisoning. The kernel has no concept of intent — it enforces access control via EPERM regardless of what the agent claims. Container isolation (namespace + cgroup), strict RBAC, stripped Linux capabilities, and SELinux/AppArmor MAC profiles provide deterministic guarantees that semantic AI parsing cannot. Agents with no .env file read permission cannot exfiltrate .env files, regardless of how they’re prompted.

April 21, 2026 · 4 min · JM00NJ
AI Agent Security: Why Container Isolation & Linux RBAC Beat AI Firewalls | Kernel-Level Access Control
DigitalOcean Referral Badge