Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Spoofing an IP over the internet |
|---|---|
| Date: | Mon, 22 Nov 2004 22:14:59 +0200 (IST) |
Hi. On Mon, 22 Nov 2004, Simon wrote:
I'm currently working in dealing with a possible DoS attack, where the user would send TCP/IP packets to the webserver with different information. Currently, I create a new Session ID if the pair [IPaddress/UserAgent] is not found. It would be easy for a hacker to just set UserAgent to an incrementing number, until the disk is filled with sessions. However, it would be very simple to just verify that one IP cannot have more than one UserAgent associated with it.
Unfortunately life is not so straightforward: a lot of legitimate users can have single IP due to proxies. Regards, ASK
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | FW: HIPAA training, Newberry, Julie S |
|---|---|
| Next by Date: | Re: Please help ! need to check IIS volunrabilities., Byron Copeland |
| Previous by Thread: | Spoofing an IP over the internet, Simon |
| Next by Thread: | Re: Spoofing an IP over the internet, Simon |
| Indexes: | [Date] [Thread] [Top] [All Lists] |