Re: RE: Session & IP Spoofing

From: Frank Knobbe (frank_at_knobbe.us)
Date: 12/05/03

  • Next message: Scovetta, Michael V: "RE: RE: Session & IP Spoofing"
    To: Nexus <nexus@patrol.i-way.co.uk>
    Date: Thu, 04 Dec 2003 18:41:09 -0600
    
    
    

    On Thu, 2003-12-04 at 09:46, Nexus wrote:
    > But you would also need to spoof the TCP 3-way handshake before you can even
    > send the HTTP GET request, which is um..... non-trivial ;-)

    I thought that IIS servers don't need the 3-way handshake. Isn't IE
    cheating by trying to send regular ACKed data packets in order to speed
    up the connection with the IIS webserver? (and falls back to TCP 3-way
    when it doesn't get a response, as is pretty much the case with all
    standards abiding web servers).

    So IIS servers may be more vulnerable against those spoofing attacks
    then, say, Apache servers.

    (and if that is the case -- testing required here -- then it's just
    another one of those situations where Microsoft ignores a standard,
    tries to cheat in favor of performance, and gets bitten with a
    vulnerability in the end...)

    Regards,
    Frank

    
    



  • Next message: Scovetta, Michael V: "RE: RE: Session & IP Spoofing"

    Relevant Pages

    • Re: WCF Architecture question
      ... WAS and write a Host as a Windows Service using TCP. ... computers which are connected to a central server via wireless. ... Using IIS has the following benefits: ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: WCF Architecture question
      ... > computers which are connected to a central server via wireless. ... Using IIS has the following benefits: ... WCF service can take advantage of the ASP.NET's compilation model. ... Wouldn't TCP be faster? ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: Cannot reach my own web server using dynamic IP
      ... Please also verify that your ISP does not block multiple ports. ... Kristofer Gafvert - IIS MVP ... > TCP 149.99.165.43:80 ...
      (microsoft.public.inetserver.iis)
    • Re: Ports Open PLEASE!!!!
      ... Tell them they need a firewall now. ... Create a mirrored rule to block all traffic. ... a mirrored rule that permits inbound ports 80 tcp and 3389 ... You should also run the IIS Lockdown tool on your IIS ...
      (microsoft.public.win2000.security)
    • RE: CodeRed Observations.
      ... We have two old IIS boxes in our lab and I checked with those. ... - There is alway a three-way tcp handshake at the beginning. ... In the meanwhile below that article about the IE/IIS communication ... Take back your personal time. ...
      (Incidents)