[Full-Disclosure] Re: SEARCH web attack (IP address spoofed?)
Martin Mačok
martin.macok at underground.cz
Thu Apr 1 14:07:10 BST 2004
On Thu, Apr 01, 2004 at 12:30:18PM +0200, i.t Consulting wrote:
> why is it likely that the source IP address is not spoofed?
If TCP initial sequence numbers are NOT predictable on your server,
the attacker cannot do full TCP handshake (she does not see the
replies - TCP SYN+ACK etc.) and so she cannot complete TCP handshake
and establish TCP connection to send (application) data through it.
(Well, I'm not 100% sure what happens with eventual data sent in TCP
SYN packet ...)
Anyway, she is (at least) able to spoof any IP address for which she
is able to see the replies - i.e. almost any other IP address on her
local network or "behind" it (say, she controls the router).
Martin Mačok
IT Security Consultant
Full-Disclosure is hosted and sponsored by Secunia.