Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: Re: SEARCH web attack (IP address spoofed?)
From: Martin Mačok <martin.macok () underground cz>
Date: Thu, 1 Apr 2004 15:07:10 +0200

On Thu, Apr 01, 2004 at 12:30:18PM +0200, i.t Consulting wrote:

why is it likely that the source IP address is not spoofed?

If TCP initial sequence numbers are NOT predictable on your server,
the attacker cannot do full TCP handshake (she does not see the
replies - TCP SYN+ACK etc.) and so she cannot complete TCP handshake
and establish TCP connection to send (application) data through it.

(Well, I'm not 100% sure what happens with eventual data sent in TCP
SYN packet ...)

Anyway, she is (at least) able to spoof any IP address for which she
is able to see the replies - i.e. almost any other IP address on her
local network or "behind" it (say, she controls the router).

Martin Mačok
IT Security Consultant

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]