Re: Net forensics question

From: Andersson (no email) (devnull@pole-position.org)
Date: Thu Jun 05 2003 - 14:49:23 PDT

  • Next message: Ryan Smith: "looking for EFS weaknesses"

    Jimi Thompson wrote:
    > Many OS's drop anything that's more than 20 or 30 hops old.
    
    No offense but I couldn't resist correcting that twisted statement.
    Some older OS's set the TTL to a low value, like 16 or 32, when 
    originating a packet. All OS's drop packets when TTL reaches zero 
    (before retransmitting). Jimi probably knows this and meant this but we 
    don't want to puzzle all the people that learns from reading lists!
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Jun 06 2003 - 04:31:22 PDT