RE: Multiple Spoofed HTTP Requests

From: Kyle Starkey (kstarkey_at_siegeworks.com)
Date: 09/03/05

  • Next message: Kaj Huisman: "Re: Multiple Spoofed HTTP Requests"
    Date: Sat, 03 Sep 2005 10:43:17 -0600
    To: pen-test@securityfocus.com
    
    

    This can be done, but requires that you are talking to a webserver whose
    sequence numbers are easily guessable and even then is going to be a blind
    attack... You will have to send the packets from a spoofed source then
    simply continue to have the conversation with the webserver without ever
    hearing the Webserver side of it... However a few "standard" convo's with
    the WS should tell you how it is going to react when you spoof the source
    IP... It's a pretty tricky attack, but it can be done assuming the WS uses
    easily guessable seq #'s and your source IP is something that is non-RFC1918
    so the packet will get to the ws and not get blocked by FW's or border
    router acls...

    -K

    -----Original Message-----
    From: kuffya@gmail.com [mailto:kuffya@gmail.com]
    Sent: Friday, September 02, 2005 7:12 AM
    To: pen-test@securityfocus.com
    Subject: Multiple Spoofed HTTP Requests

    Hi list,
    I've used a variety of tools such as Nemesis, Packet Xcalibur & Libnet GUI
    to craft customized packets. Using such tools, you can create packets at
    layers 2 up to 5 possibly spoofing your source IP, port numbers or whatever
    you see fit.
    The question is : Would it be possible to craft a HTTP request(or multiple
    requests) using a spoofed IP address? I'm inclined to consider that it's
    not, the reason being you must have a 3-way handshake established before you
    can start talking application layer protocols (such as HTTP). If you use a
    spoofed IP address, then there's no way of doing that. On the other hand, I
    might be totally wrong, that's why I'm asking the list, for the list is
    wise.
    If, however, it is possible could you please give me some directions on how
    to do it?

    Thanks a lot
    S.

    ----------------------------------------------------------------------------

    --
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for
    vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers
    do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    ----------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
    futile against web application hacking. Check your website for vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------
    

  • Next message: Kaj Huisman: "Re: Multiple Spoofed HTTP Requests"

    Relevant Pages

    • Re: Cracking WEP and WPA keys
      ... I was going off what airodump was reporting and stopped collecting ... if your packets are all ... >>Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: Scanning Class A network
      ... if you did use spoofing pick up return packets passively as they try ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • RE: an anternative to port-knoking using the OpenBSD pf only
      ... packets look like they originated on the NATting device. ... > to use a specific sequence of header fields as a key to validate ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • RE: Multiple Spoofed HTTP Requests
      ... If you can't view the return packets that you have no ... idea what the web server chose as its Initial Sequence Number. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • Re: network informations brought by cdp
      ... CDPsniffer is a smaill perl only Cisco discovery protocol ... packets and prints out the decoded protocol contents. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)

  • Quantcast