Walter, Por lo que lei hace unos d�as, la soluci�n a ese tema estar�a por el lado de hacer que la secuencia recomience por cada nueva conexi�n que se establezca desde la red privada, y no que siga indefinidamente.
Por ahora solo algunos BSDs ya hab�an implementado esta medida adicional de seguridad (m�s bien, de no buchoneo). Saludos, Andr�s --- Walter Castro <[EMAIL PROTECTED]> escribi�: > Me vino a la mente alguien que pregunto por algo asi en la lista.... > > > A Technique for Counting NATted Hosts > Steven M. Bellovin > [EMAIL PROTECTED] > AT&T Labs Research > Abstract- There have been many attempts to measure > how many hosts are on the Internet. Many of those endpoints, > however, are NAT boxes (Network Address Translators), > and actually represent several different computers. > We describe a technique for detecting NATs and counting > the number of active hosts behind them. The technique is > based on the observation that on many operating systems, > the IP header's ID field is a simple counter. By suitable > processing of trace data, packets emanating from individual > machines can be isolated, and the number of machines > determined. Our implementation, tested on aggregated local > trace data, demonstrates the feasibility (and limitations) > of the scheme. > ------------ Internet GRATIS es Yahoo! Conexi�n 4004-1010 desde Buenos Aires. Usuario: yahoo; contrase�a: yahoo M�s ciudades: http://conexion.yahoo.com.ar _______________________________________________ Lugro mailing list [EMAIL PROTECTED] http://www.lugro.org.ar/mailman/listinfo/lugro
