Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: A new TCP/IP blind data injection technique? Dec 10 2003 11:59PM
Kris Kennaway (kris FreeBSD org)
On Thu, Dec 11, 2003 at 12:28:28AM +0100, Michal Zalewski wrote:

> 2. Random IP ID numbers, a feature of some systems (OpenBSD?), although also
> risky (increasing reassembly collission probability), make the attack
> more difficult.

FreeBSD also has the option of randomizing the IP ID...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus