more about IP ID

From: antirezat_private
Date: Sat Nov 20 1999 - 09:53:14 PST

  • Next message: Solar Eclipse: "Re: WordPad/riched20.dll buffer overflow - Full Details"

    Hi,
    
    some little new ideas about IP ID issue:
    
    The first is about linux firewalling: since it increase IP ID global counter
    even if an outgoing packet will be filtered we are able, for example, to
    scan UDP ports even if ICMP type 3 output is DENY, and in general it is possible
    to know when TCP/IP stack reply a packet even if the reply is dropped.
    I think (but not tested) that this is true for almost all firewalls.
    
    The second issue concern the ability to uncover firewall rules. For example
    it is travial to know if host A filter packets from the IP X.Y.Z.W monitoring
    IP ID incresing of host A or host with X.Y.Z.W address (this changes if we are
    interested to know input or output rules) and sending packets that suppose
    some reply. Also this is related with the ability to scan the ports of hosts
    that drop all packets with a source different than host.trusted.com.
    There are others stuff like this but they are only different faces of the
    same concepts.
    
    Some people thinks that this kind of attacks isn't a "real world" attacks,
    I'm strongly interested to know what's bugtraq readers opinion (IMO this
    kind of attacks are feasible and usefull for an attacker. For exaple the
    ability to scan the ports with only spoofed packets and the ability to
    guess remote hosts traffic are a lot real).
    
    ciao,
    antirez
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:13:42 PDT