[827] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Chances of guessing?

daemon@ATHENA.MIT.EDU (Timothy Newsham)
Sat Jan 28 03:10:45 1995

From: newsham@aloha.net (Timothy Newsham)
To: bicknell@ussenterprise.async.vt.edu (Leo Bicknell)
Date: Fri, 27 Jan 1995 21:15:57 -1000 (HST)
Cc: bugtraq@fc.net
In-Reply-To: <199501271538.KAA09081@ussenterprise.async.vt.edu> from "Leo Bicknell" at Jan 27, 95 10:38:48 am

> to get in.  I'd like to avoid writing a program to exploit this
> and testing it several hundred times here to get a figure.

write a program to send out SYN's and get back SYN+ACK's and
record them,  or just record a bunch of SYN+ACK responses from
your host to other hosts along with a timestamp.  Now take
those recorded numbers and see if you can predict the
next value given the previous N values and timestamps and
the next timestamp.

tcpdump can get you sequence numbers and timestamps.

> Leo Bicknell - bicknell@vt.edu                     | Make a little birdhouse
>                bicknell@csugrad.cs.vt.edu          | in your soul......
>                bicknell@ussenterprise.async.vt.edu | They Might


home help back first fref pref prev next nref lref last post