Hacker 'handshake' hole found in common firewalls
networkworld.com
networkworld.com
For more details about the attack consider reading:
The TCP Split Handshake Attack: Practical Effects on Modern Network Equipment (BreakPoint Systems, 2010) http://nmap.org/misc/split-handshake.pdf
The standard handshake looks like:
Syn ->
<- Syn / Ack
Syn ->
The 'split handshake' looks like:
Syn ->
<- Syn
Syn / Ack ->
<- Ack
As a result, the hypothesis is that the intermediary router could incorrectly flip the roles of client and server, and incorrectly forward untrusted packets from the outside 'client'.
Could anyone explain to a simpleton how the NSS version of the attack works using only client access?
What does this say I don't even
Just change "all but one" to "only one".
"Normally when a client initiates a TCP connection to a server, PF will pass the handshake packets between the two endpoints as they arrive. PF has the ability, however, to proxy the handshake. With the handshake proxied, PF itself will complete the handshake with the client, initiate a handshake with the server, and then pass packets between the two. The benefit of this process is that no packets are sent to the server before the client completes the handshake. This eliminates the threat of spoofed TCP SYN floods affecting the server because a spoofed client connection will be unable to complete the handshake. "
Who would use security software that doesn't ship with the source code, anyway? How can you trust something that you can't even see?