Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics


Specialist Topics Suggestions for topic sections welcome!

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-18-2009, 07:25 AM
Member
 
Join Date: May 2008
Posts: 35
Default RST packet attack from Client

the RST packet attack is basically when a client initiates a connection (3 way handshake) and an attacker spoofs the identity of the server and get the correct sequence number and ACK no and sends a packet with the RST packet set to one..

but what i am trying to do is,,, reset the connection from the client its self instead of the server resetting the connection,,, so that another spoofed server can interact with the client (Victim)

so basically a client would send a request such as
Code:
pkt-1: seq #: 12345
         ack #: 54321
        flags#: PA<-PSH-ACK
       Payload: GET http://www.someserver.com/somefile.ext

how would the immediate RST Packet look like??

pkt-2: seq#: 12345+42<-(42 being the payload lenght of previous packet)
         ack#: 54321
       flags#: R<-RST
is this Right??? or does the RST packet need to have the exact same seq # as pkt-1??

Last edited by Cryptid; 10-18-2009 at 07:28 AM.
Reply With Quote
  #2 (permalink)  
Old 10-18-2009, 11:04 AM
archangel.amael's Avatar
Moderator
 
Join Date: Nov 2007
Location: behind the wire
Posts: 3,470
Default

Quote:
Originally Posted by Cryptid View Post
is this Right??? or does the RST packet need to have the exact same seq # as pkt-1??
If the sequence number is out of an expected range then it may alert Intrusion detection systems as well as some firewalls that something is not right. The problem with doing something like this is the sequence itself. Take a look at this article for a more in depth look at Sequence numbers. You can also try here there was a good bit of info about tcp sequence numbers as well, unfortunately I don't have the exact page link anymore. But there is some good info on the website none the less.
Those two should be enough to help further you along.
__________________
The very existence of flame-throwers proves that some time, somewhere, someone said to themselves, You know, I want to set those people over there on fire, but I'm just not close enough to get the job done.
George Carlin
Reply With Quote
Reply

Bookmarks

Tags
client side rst packet

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:01 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2