RE: SSH scans vs connection ratelimiting




-----Original Message-----
From: owner-freebsd-security@xxxxxxxxxxx
[mailto:owner-freebsd-security@xxxxxxxxxxx] On Behalf Of Uwe Doering
Sent: Tuesday, August 22, 2006 4:09 AM
To: freebsd-security@xxxxxxxxxxx
Subject: Re: SSH scans vs connection ratelimiting

that someone could fake a complete exchange like this from the remote
via a TCP connection while using source IP address spoofing. My
understanding so far is that source IP address spoofing from
the remote
works only with connectionless protocols like UDP and ICMP,
or TCP SYN
packets as a special case. Please correct me if I'm wrong.

You are more or less correct.

For all practical purposes, spoofing a three way tcp connection is
impossible.
(for all practical purposes)

There is man in the middle attacks, routing hijacking, and possibly tcp
connection id spoofing, but if you are using a modern os that does not
suffer from connecting id guessing, its so hard to do that that only
someone specifically trying to break into your network, who has the
ability to sniff your traffic, might even have a ghost of a chance of
doing this.

(and if you already have the *keys from known_hosts, ssh will complain
about it if it even gets that far)
--
Michael Scheidell, CTO
561-999-5000, ext 1131
SECNAP Network Security Corporation
Keep up to date with latest information on IT security: Real time
security alerts: http://www.secnap.com/news
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: iptables/backups/sound files fixed
    ... >> breaking the connection to the server before the initial estimate of the ... > The backups are send over a TCP connection, ... > need to increase some timeout. ...
    (Debian-User)
  • Deny TCP (no connection) flags RST on inside intf ? PIX 6.3.5
    ... I have recently moved from a "managed" firewall to a pix running 6.3.5; ... Built outbound TCP connection 17848999 for outside:204.54.192.17/80 ... originating hosts and the destination hosts over several days and ...
    (comp.security.firewalls)
  • Re: Keeping track of TCP retries.
    ... > customer connections which are suffering from connection problems ... > sequence numbers stay the same when a TCP connection times out and ... Which is it - retransmission of TCP segments as you imply in ... A retransmitted TCP segment will overlap in sequence space with ...
    (comp.os.linux.networking)
  • Re: Want to force TCP Connection, not Proxy HTTP
    ... selected except the one I want to use (in this example, TCP connection) ?? ... > checkboxes except TCP are selected and then click OK to the open dialogs. ... >> connects through Proxy HTTP, and uses the proxy the VPN has, so, the ...
    (microsoft.public.windowsxp.messenger)
  • Re: TCP state replication
    ... Keeps track of the "exact" current state of a TCP connection so that if there is a failure the TCP connection does not get disconnected. ... connectivity to the client-side VLAN and the other interface ... The IOM used was a 16 port Fast Ethernet Module with 288MB of memory. ...
    (bit.listserv.ibm-main)