Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: FW-1 does not prevent session hijacking? Please support claim.
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>
Date: Thu, 28 Dec 1995 12:31:05 -0500 (EST)
To: Darren Reed <avalon @ coombs . anu . edu . au>
Cc: frankw @ in . net, firewalls @ GreatCircle . COM
In-reply-to: <199512280901 . EAA04026 @ montag33 . residence . gatech . edu>

On Thu, 28 Dec 1995, Darren Reed wrote:

> > This is tough, since we can really predict bit for bit what the headers 
> > of the ACK packet that we need to send are...
> 
> It isn't really that hard.
> 
> The session being hijacked will, at one end, experience a larger number of
> ACKs than it would if it weren't there.  Also, the "real" ack's would
> indicate that one end of the connection wasn't sending data (the SEQ
> number wouldn't be changing).
> 
> However, to be able to do this, successfully, you're going to need to
> cache TCP datagrams with suspect ACK/SEQ numbers in case they happen to
> be correct.  A large number of these conflicts would be a dead giveaway.

I can see this, but there is a problem.  In order for this to work, a 
hijack must have started, and is probably 2 or 3 packets already 
underway.  By this time it might be too late.  An attacker can insert ONE 
carefully constructed ACK (w/ data) packet into the stream w/ "bad" data 
and that's all that's needed.

I would really only consider this a partial solution to the problem, and 
if someone (the attacker) figured out that this is what the progam was 
doing, they could then easily circumvent that as described above, unless 
*I* am missing something?

Brain21


Follow-Ups:
Indexed By Date Previous: Re: IP fragments and packet filters
From: mbenard @ nanaimo . ark . com (Mike)
Next: Re: Firewalls-Digest V4 #716 -Reply
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>
Indexed By Thread Previous: Re: FW-1 does not prevent session hijacking? Please support claim.
From: mbenard @ nanaimo . ark . com (Mike)
Next: Re: FW-1 does not prevent session hijacking? Please support claim.
From: Darren Reed <avalon @ coombs . anu . edu . au>

Google
 
Search Internet Search www.greatcircle.com