[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] Crafted SYN Packets...
- To: "Kelly Robinson" <caliana1989@xxxxxxxxx>
- Subject: Re: [Full-disclosure] Crafted SYN Packets...
- From: Thierry Zoller <Thierry@xxxxxxxxx>
- Date: Tue, 13 Nov 2007 23:55:36 +0100
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html><head><title></title>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<meta http-equiv="Content-Style-Type" content="text/css">
<style type="text/css"><!--
body {
margin: 5px 5px 5px 5px;
background-color: #ffffff;
}
/* ========== Text Styles ========== */
hr { color: #000000}
body, table /* Normal text */
{
font-size: 9pt;
font-family: 'Courier New';
font-style: normal;
font-weight: normal;
color: #000000;
text-decoration: none;
}
span.rvts1 /* Heading */
{
font-size: 10pt;
font-family: 'Arial';
font-weight: bold;
color: #0000ff;
}
span.rvts2 /* Subheading */
{
font-size: 10pt;
font-family: 'Arial';
font-weight: bold;
color: #000080;
}
span.rvts3 /* Keywords */
{
font-size: 10pt;
font-family: 'Arial';
font-style: italic;
color: #800000;
}
a.rvts4, span.rvts4 /* Jump 1 */
{
font-size: 10pt;
font-family: 'Arial';
color: #008000;
text-decoration: underline;
}
a.rvts5, span.rvts5 /* Jump 2 */
{
font-size: 10pt;
font-family: 'Arial';
color: #008000;
text-decoration: underline;
}
span.rvts6
{
font-size: 11pt;
font-family: 'tahoma';
font-weight: bold;
color: #ffffff;
}
span.rvts7
{
font-size: 11pt;
font-family: 'tahoma';
}
span.rvts8
{
font-size: 8pt;
font-family: 'arial';
font-style: italic;
color: #c0c0c0;
}
a.rvts9, span.rvts9
{
font-size: 8pt;
font-family: 'arial';
color: #0000ff;
text-decoration: underline;
}
/* ========== Para Styles ========== */
p,ul,ol /* Paragraph Style */
{
text-align: left;
text-indent: 0px;
padding: 0px 0px 0px 0px;
margin: 0px 0px 0px 0px;
}
.rvps1 /* Centered */
{
text-align: center;
}
--></style>
</head>
<body>
<p>Dear Kelly,</p>
<p><br></p>
<p><span class=rvts7>>If someone sends a packet with the SYN bit set to a
host, </span></p>
<p><span class=rvts7>> typically what is the client's source port? Or is
that crafted too?</span></p>
<p>Source port >1024 (normaly, please check on that, might be different from
OS to OS.</p>
<p><br></p>
<p><span class=rvts7>>Can you have a UDP SYN packet?</span></p>
<p>No UDP is as you correctly say connectionless, so no synchronisation is
required, you </p>
<p>could potential build a kind of sync feature but inside your UDP payload at
another layer.</p>
<p><br></p>
<div><table border=0 cellpadding=1 cellspacing=2 style="border-color: #000000;
border-style: solid;">
<tr valign=top>
<td width=14 style="background-color: #0000ff;">
<p><span class=rvts6>></span></p>
</td>
<td width=689 style="background-color: #ffffff;">
<p><span class=rvts7>Looking at some suspicious behaviour in our
logs...</span></p>
<p><span class=rvts7> </span></p>
<p><span class=rvts7>If someone sends a packet with the SYN bit set to a host,
typically what is the client's source port? Or is that crafted too?</span></p>
<p><span class=rvts7> </span></p>
<p><span class=rvts7>And additionally, when a client does sent a packet of this
type, am I right in assuming its generally TCP only? Can you have a UDP SYN
packet? I assume because its connectionless, no??? </span></p>
</td>
</tr>
</table>
</div>
<p><br></p>
<p><br></p>
<p><br></p>
<p><br></p>
<p><span class=rvts8>-- </span></p>
<p><a class=rvts9 href="http://secdev.zoller.lu">http://secdev.zoller.lu</a></p>
<p><span class=rvts8>Thierry Zoller</span></p>
<p><span class=rvts8>Fingerprint : 5D84 BFDC CD36 A951 2C45 2E57 28B3
75DD 0AC6 F1C7</span></p>
</body></html>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/