Re: TCP RST attack

From: Dag-Erling Smørgrav (des_at_des.no)
Date: 04/20/04

  • Next message: Mike Tancsa: "Re: TCP RST attack"
    To: Dragos Ruiu <dr@kyx.net>
    Date: Tue, 20 Apr 2004 20:26:17 +0200
    
    

    Dragos Ruiu <dr@kyx.net> writes:
    > On April 20, 2004 10:44 am, Dag-Erling Smørgrav wrote:
    > > The advisory grossly exaggerates the impact and severity of this
    > > fea^H^H^Hbug. The attack is only practical if you already know the
    > > details of the TCP connection you are trying to attack, or are in a
    > > position to sniff it.
    > This is not true. The attack does not require sniffing.

    You need to know the source and destination IP and port. In most
    cases, this means sniffing. BGP is easier because the destination
    port is always 179 and the source and destination IPs are recorded in
    the whois database, but you still need to know the source port.

    DES

    -- 
    Dag-Erling Smørgrav - des@des.no
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Mike Tancsa: "Re: TCP RST attack"

    Relevant Pages

    • Re: TCP RST attack
      ... The attack does not require sniffing. ... >You need to know the source and destination IP and port. ... While true, you do need the source port, how long will it take to ...
      (FreeBSD-Security)
    • RE: Sniffing a Switched Network
      ... Subject: Sniffing a Switched Network ... Two ways to sniff a switched network: Using a spanport on a ... to the destination port. ...
      (Security-Basics)
    • RE: Strange loopback in firefox.
      ... described as heavy attack from outside IP addresses. ... either using the Microsoft_DS port or epmap port to connect). ... For example a connection from port 3014 to 3015 and the next ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • FW: Legal? Road Runner proactive scanning.[Scanned]
      ... You consider a port scan to be an attack? ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)
    • Re: SSH server under attack...
      ... It's highly possible that even though you changed the port, an automated script discovered the new port by probing the ports and matching version numbers, ie: ... the new machine to attack me is 200.55.192.29. ... Failed password for invalid user admin from::ffff:200.55.192.29 port ...
      (Security-Basics)