Security Basics mailing list archives

session-hijacking is still available?


From: "SB CH" <chulmin2 () hotmail com>
Date: Fri, 04 Apr 2003 01:44:10 +0000

Hello, all.

if attacker can do session hijacking, he can know the seq number change, ack seq number change something like that. But I have heard that modern system like linux kernel 2.4.x or openbsd produce almost random seq number, so session hijacking is almost impossible thesedays.

is it true or not?
anyone still can session hijacking using session hijacking program like hunt?

Thanks in advance.




_________________________________________________________________
확인하자. 오늘의 운세 무료 사주, 궁합, 작명, 전생 가이드 http://www.msn.co.kr/fortune/default.asp

-------------------------------------------------------------------
SurfControl E-mail Filter puts the brakes on spam,
viruses and malicious code. Safeguard your business
critical communications. Download a free 30-day trial:
http://www.securityfocus.com/SurfControl-security-basics


Current thread: