Walter,

Por lo que lei hace unos d�as, la soluci�n a ese tema estar�a por el lado de hacer que 
la
secuencia recomience por cada nueva conexi�n que se establezca desde la red privada, y 
no
que siga indefinidamente. 

Por ahora solo algunos BSDs ya hab�an implementado esta medida adicional de seguridad
(m�s bien, de no buchoneo).

Saludos,

Andr�s



 --- Walter Castro <[EMAIL PROTECTED]> escribi�: > Me vino a la mente alguien que
pregunto por algo asi en la lista....
> 
> 
> A Technique for Counting NATted Hosts
> Steven M. Bellovin
> [EMAIL PROTECTED]
> AT&T Labs Research
> Abstract- There have been many attempts to measure
> how many hosts are on the Internet. Many of those endpoints,
> however, are NAT boxes (Network Address Translators),
> and actually represent several different computers.
> We describe a technique for detecting NATs and counting
> the number of active hosts behind them. The technique is
> based on the observation that on many operating systems,
> the IP header's ID field is a simple counter. By suitable
> processing of trace data, packets emanating from individual
> machines can be isolated, and the number of machines
> determined. Our implementation, tested on aggregated local
> trace data, demonstrates the feasibility (and limitations)
> of the scheme.
>  

------------
Internet GRATIS es Yahoo! Conexi�n
4004-1010 desde Buenos Aires. Usuario: yahoo; contrase�a: yahoo
M�s ciudades: http://conexion.yahoo.com.ar
_______________________________________________
Lugro mailing list
[EMAIL PROTECTED]
http://www.lugro.org.ar/mailman/listinfo/lugro

Responder a