Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] abnormal behavior Gmail logon

Subject: Re: [Full-disclosure] abnormal behavior Gmail logon
Date: Wed, 31 May 2006 23:18:47 +0530 (IST)
Should'nt the behaviour of a proxy in case of both RST and FIN should be same, 
i.e always a FIN. As proxy should close the connection **properly** even in 
case of a failure on the other side.

Sincerely

Ajay Pal Singh Atwal


----- David Farinic <davidfa@gfi.com> wrote:
Servers are supposed to send RST packets when they do that, but not
all
servers do it, and not all clients recognize those RST packets as
indicating that the document they just downloaded is incomplete

Most of the clients do recognize and most web servers do correctly
apply
use of RST and FIN for TCP/IP HTTP connection ending.

Problem is that some (most?)Proxy servers (nontransparent and
probably
also transparent)  DO NOT. 

I tested 4 different proxy servers if they pass RST to client's
browser
when original web server sent RST. All sent FIN instead of RST :(. (I
Did this test as I found other web apps. problems resulting from this
proxy behavior)

If anybody knows proxy which behaves 'correctly,' pls let me know.

 
Regards David Farinic 


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>