Re: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoni

看板Bugtraq作者時間18年前 (2008/02/07 02:09), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
> Interestingly enough, OpenBSD uses a flavor of this PRNG for > another field, this time the IP fragmentation ID, part of the > OpenBSD kernel network stack. The analysis carries out quite > similarly to show that OpenBSD's IP ID is predictable as well, > which gives way to O/S fingerprinting, idle-scanning, host alias > detection, traffic analysis, and in some cases, even to TCP blind > data injection. Can you expound upon the blind TCP injection allowed by IP ID prediction? > Amit Klein > CTO Trusteer Tim Newsham http://www.thenewsh.com/~newsham/
文章代碼(AID): #17gVVe00 (Bugtraq)