OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: A new TCP/IP blind data injection technique?

From: Kris Kennaway (krisFreeBSD.org)
Date: Wed Dec 10 2003 - 17:59:33 CST


On Thu, Dec 11, 2003 at 12:28:28AM +0100, Michal Zalewski wrote:

> 2. Random IP ID numbers, a feature of some systems (OpenBSD?), although also
> risky (increasing reassembly collission probability), make the attack
> more difficult.

FreeBSD also has the option of randomizing the IP ID.

Kris