<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1032319" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1032319</link>
    <description></description>
    <language>en</language>
          <item>
    <title>More info ...</title>
    <link>https://www.webmaster-forums.net/server-management/perp#comment-1189181</link>
    <description> &lt;p&gt;-&lt;br /&gt;
Technically, the spoofer could use an algorithm to &quot;guess&quot; the sequence number.  While, in such a case, local sniffing might not be necessary in order to determine the sequence number,  I am not sure how the  attacker would divine the correct IP address.&lt;/p&gt;
&lt;p&gt;I don&#039;t think that the perp is guessing anything, because most of my files are fairly small, and download quickly, and because the attacker is using only a couple bogus FIN packets per file, with a 75% success rate.&lt;br /&gt;
I am not getting a flood of overwelming numbers of bogus packets, such as would probably be necessary in order for a &quot;guessing algorithm&quot; to accomplish the task.&lt;/p&gt;
&lt;p&gt; Am i right?&lt;/p&gt;
&lt;p&gt;Two other things convince me that the culprit is between me and the Bellsouth access point:&lt;/p&gt;
&lt;p&gt;1 - Most of my customers are not static (instead, they are fairly random public-internet customers)  My guess is that the local wire could be sniffed to pick up the customer IP addresses.  &lt;/p&gt;
&lt;p&gt;2 - The bogus FIN packets are disproportionately directed to terminate zip, gz, and other archive file downloads.  &lt;/p&gt;
&lt;p&gt; - rleesBSD&lt;/p&gt;
&lt;p&gt;-excuse my edits today --- to clean up the faux pas ... hard to write well when you&#039;re irritated  &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/eyeroll.png&quot; title=&quot;Roll eyes&quot; alt=&quot;Roll eyes&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Sun, 01 Jan 2006 21:53:56 +0000</pubDate>
 <dc:creator>rleesBSD</dc:creator>
 <guid isPermaLink="false">comment 1189181 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
