Re: Systems behind NAT - port scanning etc.

From: Melinda Shore (shore@panix.com)
Date: 10/29/02


From: shore@panix.com (Melinda Shore)
Date: 28 Oct 2002 21:56:44 -0500

In article <n7mv9.44784$Ik.1041720@typhoon.sonic.net>,
leemer <kcirelli@powernetworks.biz> wrote:
>To access a currently established session and "inject" internally
>addressed(spoofed) packets and have them actually get to where you want them
>to go..(and have them come back to you at an external location) ..there's
>this really tricky thing to guess called tcp sequence numbers. They are
>almost impossible to guess.

Depends on the operating system. Aside from that, a DoS
attack, which is far, far more common than a connection
hijacking or spoofing attack, doesn't require getting a
response back from the attackee.

-- 
     Melinda Shore - Software longa, hardware brevis - shore@panix.com
          If you send me harassing email, I'll probably post it



Relevant Pages

  • Re: SYN Attacks - how i cant stop it
    ... > FBSD club, would you please review the following. ... > # control how network packets are handled after IPFW or IPFILTER ... > these MIB. ... > # the two queues which are targeted by this type of attack should ...
    (FreeBSD-Security)
  • Re: SYN Attacks - how i cant stop it
    ... > FBSD club, would you please review the following. ... > # control how network packets are handled after IPFW or IPFILTER ... > these MIB. ... > # the two queues which are targeted by this type of attack should ...
    (freebsd-questions)
  • Re: Port 80 SYN flood-like behavior
    ... > were on the receiving end of such an attack a little over one month ago. ... > across a LARGE number of TCP servers. ... > SYN/ACK packets ... ... Traffic reflection off routers ...
    (Incidents)
  • Re: Questions re WEP encryption
    ... to replay captured APR packets. ... most intrusion detection software never sees it happen. ... active attacks generate wireless traffic that can itself be detected ... and possibly alert the target of the attack. ...
    (alt.internet.wireless)
  • Re: Questions re WEP encryption
    ... to replay captured APR packets. ... subsequent attack on the same data set. ... an IDS (intrusion detection system) which would drop excessive packets ... traffic showed up in the Windows Network Control Panel. ...
    (alt.internet.wireless)

Loading