|
|
|
|
|
by bartc
4271 days ago
|
|
If your system security depends in any way on a randomly initialized TCP sequence number, you're asking for trouble. It seems it would be preferable to use predictable values so people don't get the impression that random values are somehow more secure. |
|
[1] http://wiki.cas.mcmaster.ca/index.php/The_Mitnick_attack
[2] http://phrack.org/issues/48/14.html
[3] http://phrack.org/issues/53/6.html