Re: TCP RST attack

From: Mike Tancsa (mike_at_sentex.net)
Date: 04/20/04

  • Next message: masta: "Re: TCP RST attack"
    Date: Tue, 20 Apr 2004 14:43:25 -0400
    To: des@des.no (Dag-Erling Smørgrav )
    
    

    At 02:26 PM 20/04/2004, Dag-Erling Smørgrav wrote:
    >Dragos Ruiu <dr@kyx.net> writes:
    > > On April 20, 2004 10:44 am, Dag-Erling Smørgrav wrote:
    > > > The advisory grossly exaggerates the impact and severity of this
    > > > fea^H^H^Hbug. The attack is only practical if you already know the
    > > > details of the TCP connection you are trying to attack, or are in a
    > > > position to sniff it.
    > > This is not true. The attack does not require sniffing.
    >
    >You need to know the source and destination IP and port. In most
    >cases, this means sniffing. BGP is easier because the destination
    >port is always 179 and the source and destination IPs are recorded in
    >the whois database, but you still need to know the source port.

    While true, you do need the source port, how long will it take to
    programmatically go through the possible source ports in an attack ? That
    only adds 2^16-1024 to blast through

             ---Mike

    >DES
    >--
    >Dag-Erling Smørgrav - des@des.no

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: masta: "Re: TCP RST attack"

    Relevant Pages

    • Re: TCP RST attack
      ... The attack is only practical if you already know the ... The attack does not require sniffing. ... You need to know the source and destination IP and port. ...
      (FreeBSD-Security)
    • Re: The cost of learning to drive
      ... maintenance, driver fatigue, parking problems, fines and extra danger? ... plane - and forget about it until I reach my destination. ... a very outside chance of stopping the next attack. ...
      (uk.transport)
    • Re: Port forwarding with Putty - Im stuck
      ... Source port 30025 Destination smtp.onetel.net:25 ... I'm able to uses these services properly when on the local LAN, when I SSH to the NAT'ed IP address but I've yet to try from a remote location when connecting via SSH to my public IP. ...
      (comp.security.ssh)
    • Re: Packet question
      ... What is the destination IP and port and protocol of the traffic and what is ... the source port from the server? ... You can use TCPView from SysInternals to see what ... Install a packet sniffer to see whats going on ...
      (microsoft.public.windows.server.security)
    • strange logs -- tcp port 16166
      ... All the message has the same source, source port and same destination, = ... destination port. ... world's premier technical IT security event! ...
      (Incidents)