Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Internet Firewall Vulnerabilities Part 2 of 4
From: Keinanen Vesa <vjk @ relevantum . fi>
Date: Mon, 27 Nov 1995 12:00:53 +0200 (EET)
To: Frank Willoughby <frankw @ in . net>
Cc: firewalls @ GreatCircle . com
In-reply-to: <9511260053 . AA16389 @ su1 . in . net>

On Sat, 25 Nov 1995, Frank Willoughby wrote:
> The TCP Sequence Number Prediction Attack (SNPA) relies on a somewhat
> similar technique where Bad Guy monitors the firewall traffic for a useful
> session 
> (telnet, ftp, etc.).  When the Bad Guy notices that Outside System A is 
> telneting in to Inside System C, the Bad Guy will wait until the user on A 
> has logged into Inside System C and then take over that session.  

You have wrong name for this attack. Connection hijacking has a lot
to do with TCP sequence numbers, but name "TCP Sequence Number Prediction"
describes totally different attack.

"Node Spoofing" means how to act as another host. To do this
over router network you have to master "TCP Sequence Number Prediction".
(Shimomura was attacked using this technique). This attack is 
described in "Security Problems in TCP/IP Protocol Suite":
   <http://www.research.att.com/dist/internet_security/ipext.ps.Z>
   See also <http://www.engarde.com/software/seqnum.html>

When you wan to take over existing connection, you have to do "Connection 
Hijacking" or "TCP Splicing". To see how this works, check out
document "Simple Active Attack Against TCP":
   <http://www.merit.edu/routing.arbiter/RA/security/

VK
--
Vesa Keinanen             Nasilinnankatu 24 D, 33210 Tampere, Finland
Relevantum Oy             Phone +358 31 2147200,  Fax +358 31 2147402



References:
Indexed By Date Previous: Is FlexLm secure ?
From: Peter Maersk-Moller <pm @ ghdsign . dk>
Next: Re:
From: Darren Reed <avalon @ coombs . anu . edu . au>
Indexed By Thread Previous: Re: Internet Firewall Vulnerabilities Part 2 of 4
From: Julian Assange <proff @ suburbia . net>
Next: Internet Firewall Vulnerabilities - Part 3 of 4
From: frankw @ in . net (Frank Willoughby)

Google
 
Search Internet Search www.greatcircle.com