[32843] in bugtraq

home help back first fref pref prev next nref lref last post

Re[2]: A new TCP/IP blind data injection technique?

daemon@ATHENA.MIT.EDU (Marius Huse Jacobsen)
Sat Dec 13 18:10:01 2003

Date: Sat, 13 Dec 2003 01:59:56 -0800
From: Marius Huse Jacobsen <mahuja@c2i.net>
Reply-To: Marius Huse Jacobsen <mahuja@c2i.net>
Message-ID: <12216304156.20031213015956@c2i.net>
To: bugtraq@securityfocus.com
In-Reply-To: <200312111706.hBBH6QKh011380@turing-police.cc.vt.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Valdis,

Thursday, December 11, 2003, 9:06:26 AM, you wrote:

VKve> However, it's a trivial matter to take the original text, the replacement text,
VKve> and compute an original such that the checksum comes out "the same".

Only this is a scenario where we don't have the "original text". If we
had, we could have just ripped out the sequence numbers and skipped
the whole problem.

As long as we don't know anything of the original data we have to
guess the correct checksum.

Still, 1 of 65535 is a lot better than... what is it, 2**64 ?


- --
Best regards,
 Marius                            mailto:mahuja@c2i.net

-----BEGIN PGP SIGNATURE-----

iQA/AwUBP9rjLJfZ2CSWpu1rEQIDnwCeI0wMODSSAJLgob1jSl+IDFw3uWMAoLhM
zR9zJ8TPn/0lOWXgJvBq2lZG
=CvFw
-----END PGP SIGNATURE-----


home help back first fref pref prev next nref lref last post