> A packet could be spoofed from 66.94.230.36:80. 

Fair enough, although this assumes the attacker has already positioned
himself to capture traffic between the source and destination in order
to know what to spoof.

> If the connection isn't torn down properly... it can potentially
> be hijacked.

True, again assuming the attacker has positioned himself in the middle
through routing/poisoning tricks, which presumes an above average level
of interest in cracking the target.

> Malicious packet fragments... can cause havoc when reassembled. 

I've heard that. This one is very interesting. Can you elaborate? I can
see where this would be a real problem if a reassembled packet could
point to an entirely different socket. Is that possible? Otherwise, the
attacker would have to know what process he's talking to, and what
vulnerabilities it may have, which again presumes the he has access to
packet flow.

> Depending on how your NAT device handles TCP flags, one might be able
> to trick your NAT device into passing packets. 

True, but you'd still be talking to the browser process on the client.
This is not the same as achieving an unauthorized inbound connection to
a different listening socket.

> - UDP tables are usually timer-based, leaving it live 
> until the timer expires.

Yes, again assuming the attacker already knows what source address to
spoof, and what client process he's talking to.

> All of this assumes that your NAT device is partly a firewall, 
> and is tracking state. Many don't; they just look for packets 
> with an ACK flag. If yours is one of those, then "U w1ll b3 
> 0wn3d."

So, basically, in most of the above examples (except possibly malicious
packet reassembly, which I do not yet understand) the attacker must be
in a position to have gathered significant intelligence about his
target. This usually means he has already compromised a machine at your
ISP, or he *is* your ISP. :-) He must be on something of a mission to
break into your particular network.

--Eric


DISCLAIMER: This e-mail is intended solely for the above-mentioned recipient and it 
may contain confidential or privileged information. If you have received it in error, 
please notify us immediately at 775-885-2211 and delete the e-mail. You must not copy, 
distribute, disclose or take any action in reliance on it. 

This e-mail message and any attached files have been scanned for the presence of 
computer viruses. However, you are advised that you open any attachments at your own 
risk.



DISCLAIMER: This e-mail is intended solely for the above-mentioned recipient and it 
may contain confidential or privileged information. If you have received it in error, 
please notify us immediately at 775-885-2211 and delete the e-mail. You must not copy, 
distribute, disclose or take any action in reliance on it. 

This e-mail message and any attached files have been scanned for the presence of 
computer viruses. However, you are advised that you open any attachments at your own 
risk.

_______________________________________________
RLUG mailing list
[EMAIL PROTECTED]
http://www.rlug.org/mailman/listinfo/rlug

Reply via email to