Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Full-disclosure] abnormal behavior Gmail logon |
|---|---|
| Date: | Wed, 31 May 2006 14:38:19 +0200 |
Servers are supposed to send RST packets when they do that, but not all servers do it, and not all clients recognize those RST packets as indicating that the document they just downloaded is incomplete
Most of the clients do recognize and most web servers do correctly apply use of RST and FIN for TCP/IP HTTP connection ending. Problem is that some (most?)Proxy servers (nontransparent and probably also transparent) DO NOT. I tested 4 different proxy servers if they pass RST to client's browser when original web server sent RST. All sent FIN instead of RST :(. (I Did this test as I found other web apps. problems resulting from this proxy behavior) If anybody knows proxy which behaves 'correctly,' pls let me know. Regards David Farinic -----Original Message----- From: full-disclosure-bounces@lists.grok.org.uk [mailto:full-disclosure-bounces@lists.grok.org.uk] On Behalf Of Brian Eaton Sent: Wednesday, May 31, 2006 2:25 PM To: Valdis.Kletnieks@vt.edu Cc: full-disclosure@lists.grok.org.uk; Edward Pearson Subject: Re: [Full-disclosure] abnormal behavior Gmail logon On 5/31/06, Valdis.Kletnieks@vt.edu <Valdis.Kletnieks@vt.edu> wrote:
On Wed, 31 May 2006 09:23:08 BST, Edward Pearson said:This isn't abnormal or weird, It happens when your internet
connection
is fairly slow and its because you sometimes receive incomplete
headers
for the page (broken or garbled)If you have noisy hardware that's mangling data in transit, the
mangling will
*usually* be detected by the checksums on each IP packet. The reason
your
connection gets slow is because if a corruption is detected, the
packet gets
thrown out, and needs to be retransmitted by the sending system.
It is actually possible that the data sent in the HTTP connection is getting mangled even though the TCP checksums are correct. In one mode of operation, HTTP allows a server to indicate when a document is complete simply by closing a TCP connection. If the server gets busy, it might decide your client is just too slow to be worth dealing with and close the connection early. Servers are supposed to send RST packets when they do that, but not all servers do it, and not all clients recognize those RST packets as indicating that the document they just downloaded is incomplete. Regards, Brian This mail was checked for viruses by GFI MailSecurity. GFI also develops anti-spam software (GFI MailEssentials), a fax server (GFI FAXmaker), and network security and management software (GFI LANguard) - www.gfi.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] SUSE Security Announcement: cron local privilege escalation (SUSE-SA:2006:027), Marcus Meissner |
|---|---|
| Next by Date: | [Full-disclosure] Secunia Research: Eserv/3 IMAP and HTTP Server Multiple Vulnerabilities, Secunia Research |
| Previous by Thread: | Re: [Full-disclosure] abnormal behavior Gmail logon, Brian Eaton |
| Next by Thread: | Re: [Full-disclosure] abnormal behavior Gmail logon, Ajay Pal Singh Atwal |
| Indexes: | [Date] [Thread] [Top] [All Lists] |