Vulnerability Development mailing list archives

Re: TCP Sequence Prediction


From: vlad () SANDY RU (Vladimir Dubrovin)
Date: Thu, 30 Mar 2000 12:00:38 +0400


Hello Dean Michael Dorman,

Read MS security issue:
http://www.microsoft.com/technet/security/bulletin/ms99-046.asp
"Patch Available to Improve TCP Initial Sequence Number Randomness"

For SP6a patch available at
http://download.microsoft.com/download/winntsrv40/Patch/TCP-SP6/NT4/EN-US/q243835i.exe

29.03.00 22:16, you wrote: TCP Sequence Prediction;

D> Pardon me if this is a trivial question but after nmapping several servers I
D> find that NT boxen usually come up with:

D> TCP Sequence Prediction: Class=trivial time dependency
D>                          Difficulty=6 (Trivial joke)

D> I was wondering how to increase the security here (besides removing NT and
D> installing OpenBSD).

D> _____________________________________
D> Dean Michael Dorman, Information Systems
D> Putnam Company, Wellsboro, PA  16901
D> -------------------------------------------------------------
D> Challenge the integrity of your information.
D> -------------------------------------------------------------

  +=-=-=-=-=-=-=-=-=+
  |Vladimir Dubrovin|
  | Sandy Info, ISP |
  +=-=-=-=-=-=-=-=-=+


Current thread: