Search:     Advanced search
server monitoring

Weak Initial Sequence Number

Article ID: 11057
Last updated: 27 Jan, 2009
Views: 465
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Weak Initial Sequence Number

This script is Copyright (C) 2002 Renaud Deraison

FamilyFirewalls
Plugin ID11057
Bugtraq ID5387
8652
CVE IDCVE-2002-1463

Description:

The remote host seems to generate Initial Sequence Numbers (ISN) in a weak
manner which seems to solely depend on the source and dest port of the TCP
packets.

An attacker may exploit this flaw to establish spoofed connections to the
remote host.

The Raptor Firewall and Novell Netware are known to be vulnerable to this
flaw, although other network devices may be vulnerable as well.


Solution :

If you are using a Raptor Firewall, see
http://www.symantec.com/techsupp/bulletin/archive/firewall/082002firewall.html

Otherwise, contact your vendor for a patch.

Reference : http://online.securityfocus.com/archive/1/285729

Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
L2TP detection     Arkoon Appliance Identification