<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6256684586716847588.post3830729750342598028..comments</id><updated>2010-06-17T17:21:28.185-07:00</updated><category term='Scapy'/><category term='4G'/><category term='Decode As'/><category term='Wireless'/><category term='Steve Jobs'/><category term='MetaSploit'/><category term='NBNSpoof'/><category term='iphone'/><category term='face time'/><category term='H.264'/><category term='Wireshark'/><category term='Spoof'/><category term='Papa Esteban'/><category term='SIP'/><category term='NBNS'/><category term='XMPP'/><category term='SSL'/><category term='H264'/><category term='facetime'/><category term='Apple'/><category term='Jabber'/><category term='NoBacon'/><title type='text'>Comments on Packetstan: IDS/IPS Evasion - Step 1. Awareness</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.packetstan.com/feeds/3830729750342598028/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html'/><author><name>Mike Poor</name><uri>http://www.blogger.com/profile/17876103130871711653</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>18</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-4609012336278379841</id><published>2010-06-17T17:21:28.177-07:00</published><updated>2010-06-17T17:21:28.177-07:00</updated><title type='text'>Marcos - great to hear from you.  Glad this was he...</title><content type='html'>Marcos - great to hear from you.  Glad this was helpful.  When I get some time, I&amp;#39;m going to post the Scapy code for this.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4609012336278379841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4609012336278379841'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276820488177#c4609012336278379841' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-4879978285675137671</id><published>2010-06-17T09:28:33.791-07:00</published><updated>2010-06-17T09:28:33.791-07:00</updated><title type='text'>Hi Judy,

Great article!  This just solidifies my ...</title><content type='html'>Hi Judy,&lt;br /&gt;&lt;br /&gt;Great article!  This just solidifies my love for Scapy.  This will be great for our QA testing in house.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4879978285675137671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4879978285675137671'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276792113791#c4879978285675137671' title=''/><author><name>Marcos</name><uri>http://www.blogger.com/profile/07078273374556718685</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-425153579'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-6455450785421805934</id><published>2010-06-16T11:00:30.735-07:00</published><updated>2010-06-16T11:00:30.735-07:00</updated><title type='text'>Dude, great article. Now, if only you could make t...</title><content type='html'>Dude, great article. Now, if only you could make that font legible enough without having to zoom in using magnifier...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6455450785421805934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6455450785421805934'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276711230735#c6455450785421805934' title=''/><author><name>Kulin</name><uri>http://www.blogger.com/profile/04475611294197564646</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-863976691'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-1961599804862357136</id><published>2010-06-16T09:08:10.833-07:00</published><updated>2010-06-16T09:08:10.833-07:00</updated><title type='text'>I kept thinking about this, and ended up writing a...</title><content type='html'>I kept thinking about this, and ended up writing a blog posting about how I see the specifics working. &lt;br /&gt;&lt;br /&gt;http://blog.bmurray.ca/2010/06/idsips-evasion-with-syncookies/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/1961599804862357136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/1961599804862357136'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276704490833#c1961599804862357136' title=''/><author><name>Brian</name><uri>http://www.blogger.com/profile/13851295432353004612</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1727099168'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-682384816230026846</id><published>2010-06-16T03:18:56.633-07:00</published><updated>2010-06-16T03:18:56.633-07:00</updated><title type='text'>I just wanted to reiterate that this is not a univ...</title><content type='html'>I just wanted to reiterate that this is not a universal evasion against Snort.  This &amp;quot;issue&amp;quot; was discovered when I worked on stream5 research at Sourcefire.  As I mentioned yesterday, the default stream5 policy of &amp;quot;windows&amp;quot; will actually not be fooled by this because of what it considers an invalid reset sequence number.&lt;br /&gt;&lt;br /&gt;At Sourcefire, we never truly understood this weird behavior. As Ashok astutely commented - it is a protection mechanism against SYN flooding that is implemented by SYN cookies.  I sent this information to Steve Sturges,the author of stream5, at Sourcefire.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/682384816230026846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/682384816230026846'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276683536633#c682384816230026846' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-2604222870855376521</id><published>2010-06-16T03:10:40.408-07:00</published><updated>2010-06-16T03:10:40.408-07:00</updated><title type='text'>famousjs - That was the next post I was planning o...</title><content type='html'>famousjs - That was the next post I was planning on doing!  I&amp;#39;m going to cover it  again in some detail so please don&amp;#39;t think I&amp;#39;m pirating your idea.  Thanks for the post.  One of my motivations for this and many of the other blogs I plan to do is to show how awesome Scapy is.  Thanks for helping me in this regard.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2604222870855376521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2604222870855376521'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276683040408#c2604222870855376521' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-6208798538738334418</id><published>2010-06-15T22:21:45.304-07:00</published><updated>2010-06-15T22:21:45.304-07:00</updated><title type='text'>Judy, I just posted a blog with a sample scapy scr...</title><content type='html'>Judy, I just posted a blog with a sample scapy script using this evasion technique.&lt;br /&gt;&lt;br /&gt;http://www.malforge.com/node/35&lt;br /&gt;&lt;br /&gt;Thanks for the packet-crafting fun!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6208798538738334418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6208798538738334418'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276665705304#c6208798538738334418' title=''/><author><name>famousjs</name><uri>http://www.blogger.com/profile/15375397969965201367</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1390179270'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-2896682959023662978</id><published>2010-06-15T09:41:46.802-07:00</published><updated>2010-06-15T09:41:46.802-07:00</updated><title type='text'>stream5 would have to handle this as an OS-specifi...</title><content type='html'>stream5 would have to handle this as an OS-specific policy because not all OS&amp;#39;s respond this way.  Some of stream5&amp;#39;s policies ensure that the sequence number on the reset is the next expected one - in other words one more than the last value - not two more as seen in the above reset.  If this is the case, Snort will not be fooled.  This is not a universal policy because some OS&amp;#39;s allow a reset to be any value in the current window.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2896682959023662978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2896682959023662978'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276620106802#c2896682959023662978' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-6170642181446796720</id><published>2010-06-15T08:34:10.565-07:00</published><updated>2010-06-15T08:34:10.565-07:00</updated><title type='text'>This is almost definitely a syncookie thing. Since...</title><content type='html'>This is almost definitely a syncookie thing. Since the linux host is using its magic algorithm to generate a sequence number, you could theoretically open a SYN-less connection, if you knew the magic data. Since syncookies uses the source and destination host and port numbers as part of its hash, using a ack + 2 wont validate against its syncookies algorithm, but using ack + 1 will validate. So to the webserver (in this case), doesn&amp;#39;t actually have any entries in its table until that second connection (ack + 1) opens it. &lt;br /&gt;&lt;br /&gt;I suppose someone now needs to write a patch for IDS&amp;#39;s to understand syncookies a little better. I wish I had the time to set up snort to test this, but syncookies most definitely does look like the culprit. &lt;br /&gt;&lt;br /&gt;Now the next question is why does stream5 handle it better. Interesting thing to look into.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6170642181446796720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/6170642181446796720'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276616050565#c6170642181446796720' title=''/><author><name>Brian</name><uri>http://www.blogger.com/profile/13851295432353004612</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1727099168'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-839856778047302835</id><published>2010-06-15T08:22:11.022-07:00</published><updated>2010-06-15T08:22:11.022-07:00</updated><title type='text'>oops, did not notice the &amp;quot;ACK 1&amp;quot; in pack...</title><content type='html'>oops, did not notice the &amp;quot;ACK 1&amp;quot; in packet 5, so it will make syn-cookie happy. &lt;br /&gt;&lt;br /&gt;but i do recall seeing something like syn-cookie won&amp;#39;t kick in until a certain number is reached. (i might be wrong)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/839856778047302835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/839856778047302835'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276615331022#c839856778047302835' title=''/><author><name>Life</name><uri>http://www.blogger.com/profile/02879289282253554267</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-881826438'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-7179134464047587490</id><published>2010-06-15T08:10:22.964-07:00</published><updated>2010-06-15T08:10:22.964-07:00</updated><title type='text'>hmm, i am not sure this is really caused by syn-co...</title><content type='html'>hmm, i am not sure this is really caused by syn-cookies, on some linux, syn-cookie is enabled by default but they won&amp;#39;t kick in until some threshold has been reached. &lt;br /&gt;&lt;br /&gt;also, even if syn-cookier kicks in, it should wait for the ACK, and decrypt the sequence number, and the &amp;quot;ACK 2&amp;quot; just won&amp;#39;t match...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/7179134464047587490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/7179134464047587490'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276614622964#c7179134464047587490' title=''/><author><name>Life</name><uri>http://www.blogger.com/profile/02879289282253554267</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-881826438'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-5094172361000317746</id><published>2010-06-15T07:21:24.852-07:00</published><updated>2010-06-15T07:21:24.852-07:00</updated><title type='text'>Great post Judy. I might add this in to Rule2Alert...</title><content type='html'>Great post Judy. I might add this in to Rule2Alert to stress test systems such as Snort.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/5094172361000317746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/5094172361000317746'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276611684852#c5094172361000317746' title=''/><author><name>famousjs</name><uri>http://www.blogger.com/profile/15375397969965201367</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1390179270'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-3820029090178305889</id><published>2010-06-15T03:53:02.593-07:00</published><updated>2010-06-15T03:53:02.593-07:00</updated><title type='text'>Ashok - Wow, thanks so much for the insight!  That...</title><content type='html'>Ashok - Wow, thanks so much for the insight!  That&amp;#39;s amazing to associate this behavior with SYN cookies - now I better understand the seemingly bizarre behavior.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/3820029090178305889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/3820029090178305889'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276599182593#c3820029090178305889' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-7889919256142740162</id><published>2010-06-15T03:50:56.416-07:00</published><updated>2010-06-15T03:50:56.416-07:00</updated><title type='text'>Brian - It looks like Ashok has the answer why Lin...</title><content type='html'>Brian - It looks like Ashok has the answer why Linux does this because it uses SYN cookies.  I just checked on the Linux system I use:&lt;br /&gt;&lt;br /&gt;sysctl -a | grep net.ipv4.tcp_syncookies&lt;br /&gt;net.ipv4.tcp_syncookies = 1&lt;br /&gt;&lt;br /&gt;IIRC, if Snort is configured to use preprocessor stream5_tcp: policy windows, I believe it will not be duped into resetting the connection.  I know this isn&amp;#39;t intuitive since we&amp;#39;re using Linux, and I&amp;#39;m not necessarily recommending it, it&amp;#39;s just the way that the stream5 preprocessor handles reset sequence numbers.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/7889919256142740162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/7889919256142740162'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276599056416#c7889919256142740162' title=''/><author><name>Judy Novak</name><uri>http://www.blogger.com/profile/09261837204289632199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-578991073'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-4953251311436287462</id><published>2010-06-15T01:41:07.286-07:00</published><updated>2010-06-15T01:41:07.286-07:00</updated><title type='text'>Hi Judy, I think this kind of behavior is expected...</title><content type='html'>Hi Judy, I think this kind of behavior is expected with any implementation using syn-cookie, (which explains why you don&amp;#39;t see the SYN+ACK being retransmitted), as the wrong ACK is  just a stray packet and the GET is considered as valid final ACK of three-way handshake since the syn-cookie will match.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4953251311436287462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/4953251311436287462'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276591267286#c4953251311436287462' title=''/><author><name>Ashok</name><uri>http://www.blogger.com/profile/06606142257862151156</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-899055298'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-8563866611799712407</id><published>2010-06-15T01:22:53.548-07:00</published><updated>2010-06-15T01:22:53.548-07:00</updated><title type='text'>Very Nice, at one point i was really close to gras...</title><content type='html'>Very Nice, at one point i was really close to grasping this possibility. But the actual proof of such attack-vector being plausible is a thumbs-up for my natural paranoid state of being.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/8563866611799712407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/8563866611799712407'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276590173548#c8563866611799712407' title=''/><author><name>J.L.</name><uri>http://www.blogger.com/profile/08797451038320629198</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-622749780'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-8140197496932709049</id><published>2010-06-14T21:41:13.780-07:00</published><updated>2010-06-14T21:41:13.780-07:00</updated><title type='text'>Judy, as always, nice work.  Look forward to seein...</title><content type='html'>Judy, as always, nice work.  Look forward to seeing more.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/8140197496932709049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/8140197496932709049'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276576873780#c8140197496932709049' title=''/><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/05018134738510159518</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_BpBcl5urwoc/SGEd_P7nmEI/AAAAAAAAAKA/EJkaqvwmX0o/S220/Headshot.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-891212324'/></entry><entry><id>tag:blogger.com,1999:blog-6256684586716847588.post-2986845492980158151</id><published>2010-06-14T19:35:49.687-07:00</published><updated>2010-06-14T19:35:49.687-07:00</updated><title type='text'>Very interesting. I wonder if it&amp;#39;s by design o...</title><content type='html'>Very interesting. I wonder if it&amp;#39;s by design or a bug. Do you know what ids systems this affects? &lt;br /&gt;&lt;br /&gt;Also, the colour scheme burns my eyes. It even comes through as white on my rss reader, making it nearly impossible to read. You may want to reconsider that decision.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2986845492980158151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6256684586716847588/3830729750342598028/comments/default/2986845492980158151'/><link rel='alternate' type='text/html' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html?showComment=1276569349687#c2986845492980158151' title=''/><author><name>Brian</name><uri>http://www.blogger.com/profile/13851295432353004612</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html' ref='tag:blogger.com,1999:blog-6256684586716847588.post-3830729750342598028' source='http://www.blogger.com/feeds/6256684586716847588/posts/default/3830729750342598028' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1727099168'/></entry></feed>
