Home page logo
/

firewall-wizards logo Firewall Wizards mailing list archives

RE: FW Sequence Number based statefulness
From: Carson Gaspar <carson () taltos org>
Date: Mon, 14 May 2001 14:37:43 -0700



--On Monday, May 14, 2001 2:18 PM -0700 Peter Crocker <pcrocker () netscreen com> wrote:

window. (The window may use an appropriately selected fixed value, say 32
or 64K, rather than strictly monitoring the window. The implementation

No, it may not. If you do, you'll break large window support. You either must make it the largest legal scaled window (which makes for rather easy sequence spoofing), or you have to monitor the actual window negotiation, or (best) monitor the actual windows being transmitted.

--
Carson

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]