<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Trehb101.com - Got Geek? &#187; TCP</title>
	<atom:link href="http://www.trehb101.com/index.php/tag/tcp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.trehb101.com</link>
	<description>Information Security : Technology : Project Management : Life</description>
	<lastBuildDate>Thu, 31 Mar 2011 22:23:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – More Protocols</title>
		<link>http://www.trehb101.com/index.php/2010/03/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-more-protocols/</link>
		<comments>http://www.trehb101.com/index.php/2010/03/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-more-protocols/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 18:22:31 +0000</pubDate>
		<dc:creator>TheDon</dc:creator>
				<category><![CDATA[Don's eBook Report]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Address Resolution Protocol]]></category>
		<category><![CDATA[ARP]]></category>
		<category><![CDATA[Bootp]]></category>
		<category><![CDATA[Bootstrap protocol]]></category>
		<category><![CDATA[CISSP RE]]></category>
		<category><![CDATA[File Transfer Protocol]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[ICMP]]></category>
		<category><![CDATA[Internet Control Message Protocol]]></category>
		<category><![CDATA[Internet Protocol]]></category>
		<category><![CDATA[Network File Sharing]]></category>
		<category><![CDATA[NFS]]></category>
		<category><![CDATA[RARP]]></category>
		<category><![CDATA[Reverse Address Resolution Protocol]]></category>
		<category><![CDATA[Simple Network Management Protocol]]></category>
		<category><![CDATA[SNMP]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[TCP/IP]]></category>
		<category><![CDATA[telnet]]></category>
		<category><![CDATA[TFTP]]></category>
		<category><![CDATA[Transmission Control Protocol]]></category>
		<category><![CDATA[Trivial FTP]]></category>
		<category><![CDATA[UDP]]></category>

		<guid isPermaLink="false">http://www.trehb101.com/?p=342</guid>
		<description><![CDATA[TCP – Transmission Control Protocol

    * Connection oriented
    * Sequenced packets
    * Acknowledgement is sent back for received packets
    * If no acknowledgement then packet is resent
    * Packets are re-sequenced
    * Manageable data flow is maintained]]></description>
			<content:encoded><![CDATA[<p><strong>Host-to-Host Transport Layer Protocols</strong></p>
<p><strong>TCP – Transmission Control Protocol</strong></p>
<ul>
<li>Connection oriented</li>
<li>Sequenced packets</li>
<li>Acknowledgement is sent back for received packets</li>
<li>If no acknowledgement then packet is resent</li>
<li>Packets are re-sequenced</li>
<li>Manageable data flow is maintained</li>
</ul>
<p><strong>Note: </strong>TCP and UDP use dynamic port numbers greater than 1023</p>
<p style="text-align: center;"><a href="http://www.amazon.com/Shon-Harris-CISSP-Video-Seminar/dp/B000VAUVRG%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000VAUVRG" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Shon-Harris-CISSP-Video-Seminar/dp/B000VAUVRG_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB000VAUVRG?referer=');"><img src="http://ecx.images-amazon.com/images/I/51IKv2zbVuL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/Shon-Harris-CISSP-Solution/dp/B000AYWNWY%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000AYWNWY" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Shon-Harris-CISSP-Solution/dp/B000AYWNWY_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB000AYWNWY?referer=');"><img src="http://ecx.images-amazon.com/images/I/5128347HN8L._SL75_.jpg" alt="" /> </a><a href="http://www.amazon.com/CISSP-Certification-Practice-Study-Bundle/dp/B001W8U2ZM%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB001W8U2ZM" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/CISSP-Certification-Practice-Study-Bundle/dp/B001W8U2ZM_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB001W8U2ZM?referer=');"><img src="http://ecx.images-amazon.com/images/I/51ci8WP45uL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/CISSP-All-One-Guide-Fifth/dp/0071602178%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3D0071602178" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/CISSP-All-One-Guide-Fifth/dp/0071602178_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3D0071602178?referer=');"><img src="http://ecx.images-amazon.com/images/I/51OQJcG0itL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/Official-Guide-CISSP-Second-Press/dp/1439809593%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3D1439809593" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Official-Guide-CISSP-Second-Press/dp/1439809593_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3D1439809593?referer=');"><img src="http://ecx.images-amazon.com/images/I/414%2BZSmZO6L._SL75_.jpg" alt="" /></a></p>
<p><span id="more-342"></span></p>
<p><strong>UDP</strong></p>
<ul>
<li>Best effort</li>
<li>Doesn’t care about sequence order</li>
<li>Connectionless</li>
<li>Less overhead and faster than TCP</li>
</ul>
<p><!--Start CISSP ebook ad--></p>
<table border="0" width="100%">
<tbody>
<tr>
<td bgcolor="#ffcc99">
<h1 style="text-align: center;"><strong>Planning to take the CISSP Exam? </strong></h1>
<h2><strong>Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only <span class="style1">$25.00</span>.</strong></h2>
<div><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 110px"><strong><strong><a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/"><img title="CISSP Exam Review Notes" src="http://www.trehb101.com/images/entries/CISSP-Review-Notes-PACK-small.png" alt="Click the Add To Cart Button to Purchase" width="100" height="192" /></a></strong></strong><p class="wp-caption-text">Click the Add To Cart Button to Purchase</p></div>
<p><strong>Plus you will also get copies of notes from other CISSPs. </strong></p>
<p><strong>Learn more about this package by visiting this blog entry: <a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/">CISSP REVIEW NOTES I USED TO PASS THE  EXAM. </a></strong></div>
<p style="text-align: center;" align="center"><strong>CLICK BELOW TO MAKE YOUR PURCHASE NOW. </strong></p>
<p style="text-align: center;" align="center"><strong><object><form method="post"  action=""  style="display:inline" onsubmit="return ReadForm(this, true);"><input type="submit" value="Add to Cart" /><input type="hidden" name="product" value="CISSP Review Notes Package" /><input type="hidden" name="price" value="25.00" /><input type="hidden" name="product_tmp" value="CISSP Review Notes Package" /><input type="hidden" name="addcart" value="1" /></form></object></strong></p>
<p style="text-align: center;" align="center">All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.</p>
<p style="text-align: center;" align="center"><strong>IMPORTANT NOTICE: </strong></p>
<p style="text-align: center;" align="center">I  MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE  WILL BE SOME DELAY ON YOU RECEIVING AN E-MAIL FROM ME WITH THE LINK TO  THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME  WITHIN 24-48 HOURS.</p>
</td>
</tr>
</tbody>
</table>
<p><!--End CISSP ebook ad--></p>
<p><strong>Internet Layer Protocols</strong></p>
<p><strong> </strong></p>
<p><strong>IP – Internet Protocol</strong></p>
<ul>
<li>All hosts on a network have an IP address</li>
<li>Each data packet is assigned the IP address of      the sender and the receiver</li>
<li>It provides an “unreliable datagram” services</li>
<li>Provides:
<ul>
<li>No guarantees that the packet will be delivered</li>
<li>No guarantee that the packet will be delivered only       once</li>
<li>No guarantee that it will be delivered in the       order in which it was sent</li>
</ul>
</li>
</ul>
<p><strong>ARP – Address Resolution Protocol</strong></p>
<ul>
<li>Use the IP Address to get the MAC address</li>
<li>MAC Address is 48 bit</li>
<li>IP address is 32 bit</li>
<li>Only broadcast to network first time, otherwise      stores IP and MAC info in table</li>
</ul>
<p><strong>RARP – Reverse Address Resolution Protocol</strong></p>
<ul>
<li>Use the MAC address to get the IP address</li>
<li>RARP Server tells diskless machines’ IP address</li>
</ul>
<p><strong>ICMP – Internet Control Message Protocol</strong></p>
<ul>
<li>Management Protocol and messaging service      provider for IP</li>
<li>Sends messages between network devices regarding      the health of the network</li>
<li>Ping is ICMP packet</li>
<li>Ping checks if a host is up and operational</li>
</ul>
<p><strong>Note: </strong>TCP/IP does not define physical standards it uses existing ones</p>
<p><strong>Other TCP/IP Protocols</strong></p>
<p><strong>Telnet </strong></p>
<ul>
<li>Terminal Emulation</li>
<li>No File Transfer</li>
</ul>
<p><strong> </strong></p>
<p><strong>FTP </strong></p>
<ul>
<li>File Transfer Protocol</li>
<li>Can not execute files</li>
</ul>
<p><strong> </strong></p>
<p><strong>TFTP</strong></p>
<ul>
<li>Trivial FTP</li>
<li>No directory browsing capabilities, no      authentication</li>
<li>Can only send and receive files</li>
<li>UDP-base file transfer program that provides no      security</li>
</ul>
<p><strong>NFS – </strong>Network File Sharing</p>
<p><strong>SMTP –</strong> Delivers e-mails</p>
<p><strong>X-Windows &#8211; </strong>For writing graphical interface applications</p>
<p><strong>SNMP</strong></p>
<ul>
<li>Simple Network Management Protocol<strong> </strong></li>
<li>Provides for the collection of network      information by polling the devices on the network from a management      station<strong> </strong></li>
<li>Sends SNMP traps (notification) to  MIBS – Management Information Bases<strong> </strong></li>
</ul>
<p><strong>Bootstrap Protocol (BootP)</strong></p>
<ul>
<li>Diskless bootup</li>
<li>BootP server hears the request and looks up the      client’s MAC address in its BootP file</li>
<li>Internet Layer Protocol</li>
</ul>
<p style="text-align: center;"><a href="http://www.amazon.com/Shon-Harris-CISSP-Video-Seminar/dp/B000VAUVRG%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000VAUVRG" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Shon-Harris-CISSP-Video-Seminar/dp/B000VAUVRG_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB000VAUVRG?referer=');"><img src="http://ecx.images-amazon.com/images/I/51IKv2zbVuL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/Shon-Harris-CISSP-Solution/dp/B000AYWNWY%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000AYWNWY" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Shon-Harris-CISSP-Solution/dp/B000AYWNWY_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB000AYWNWY?referer=');"><img src="http://ecx.images-amazon.com/images/I/5128347HN8L._SL75_.jpg" alt="" /> </a><a href="http://www.amazon.com/CISSP-Certification-Practice-Study-Bundle/dp/B001W8U2ZM%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB001W8U2ZM" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/CISSP-Certification-Practice-Study-Bundle/dp/B001W8U2ZM_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3DB001W8U2ZM?referer=');"><img src="http://ecx.images-amazon.com/images/I/51ci8WP45uL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/CISSP-All-One-Guide-Fifth/dp/0071602178%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3D0071602178" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/CISSP-All-One-Guide-Fifth/dp/0071602178_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3D0071602178?referer=');"><img src="http://ecx.images-amazon.com/images/I/51OQJcG0itL._SL75_.jpg" alt="" /></a><a href="http://www.amazon.com/Official-Guide-CISSP-Second-Press/dp/1439809593%3FSubscriptionId%3DAKIAIEOUDPPDBC477XGA%26tag%3Dgutomorg-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3D1439809593" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/Official-Guide-CISSP-Second-Press/dp/1439809593_3FSubscriptionId_3DAKIAIEOUDPPDBC477XGA_26tag_3Dgutomorg-20_26linkCode_3Dxm2_26camp_3D2025_26creative_3D165953_26creativeASIN_3D1439809593?referer=');"><img src="http://ecx.images-amazon.com/images/I/414%2BZSmZO6L._SL75_.jpg" alt="" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.trehb101.com/index.php/2010/03/10/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-more-protocols/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – Session Hijacking</title>
		<link>http://www.trehb101.com/index.php/2009/12/11/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-session-hijacking/</link>
		<comments>http://www.trehb101.com/index.php/2009/12/11/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-session-hijacking/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 19:47:49 +0000</pubDate>
		<dc:creator>TheDon</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[CISSP Exam Review]]></category>
		<category><![CDATA[E-mail Spoofing]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[IP packets]]></category>
		<category><![CDATA[IP Spoofing]]></category>
		<category><![CDATA[man-in-the-middle attack]]></category>
		<category><![CDATA[session hijacking]]></category>
		<category><![CDATA[source-routing]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[TCP Sequence Number]]></category>

		<guid isPermaLink="false">http://www.trehb101.com/?p=258</guid>
		<description><![CDATA[In computer science, session hijacking refers to the exploitation of a valid computer session—sometimes also called a session key—to gain unauthorized access to information or services in a computer system. In particular, it is used to refer to the theft of a magic cookie used to authenticate a user to a remote server. It has particular relevance to web developers, as the HTTP cookies used to maintain a session on many web sites can be easily stolen by an attacker using an intermediary computer or with access to the saved cookies on the victim's computer (see HTTP cookie theft).]]></description>
			<content:encoded><![CDATA[<p>In computer science, session hijacking refers to the exploitation of a valid computer session—sometimes also called a session key—to gain unauthorized access to information or services in a computer system. In particular, it is used to refer to the theft of a magic cookie used to authenticate a user to a remote server. It has particular relevance to web developers, as the HTTP cookies used to maintain a session on many web sites can be easily stolen by an attacker using an intermediary computer or with access to the saved cookies on the victim&#8217;s computer (see HTTP cookie theft).</p>
<p>TCP session hijacking is when a hacker takes over a TCP session between two machines. Since most authentication only occurs at the start of a TCP session, this allows the hacker to gain access to a machine.<span id="more-258"></span></p>
<p><!--Start CISSP ebook ad--></p>
<table border="0" width="100%">
<tbody>
<tr>
<td bgcolor="#ffcc99">
<h1 style="text-align: center;"><strong>Planning to take the CISSP Exam? </strong></h1>
<h2><strong>Get a copy of my personal notes (300plus pages worth) that I used to pass the exam for only <span class="style1">$25.00</span>.</strong></h2>
<div><strong> </strong></p>
<div class="wp-caption alignleft" style="width: 110px"><strong><strong><a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/"><img title="CISSP Exam Review Notes" src="http://www.trehb101.com/images/entries/CISSP-Review-Notes-PACK-small.png" alt="Click the Add To Cart Button to Purchase" width="100" height="192" /></a></strong></strong><p class="wp-caption-text">Click the Add To Cart Button to Purchase</p></div>
<p><strong>Plus you will also get copies of notes from other CISSPs. </strong></p>
<p><strong>Learn more about this package by visiting this blog entry: <a href="http://www.trehb101.com/index.php/2009/11/18/cissp-review-notes-notes-i-used-to-pass-the-exam/">CISSP REVIEW NOTES I USED TO PASS THE  EXAM. </a></strong></div>
<p style="text-align: center;" align="center"><strong>CLICK BELOW TO MAKE YOUR PURCHASE NOW. </strong></p>
<p style="text-align: center;" align="center"><strong><object><form method="post"  action=""  style="display:inline" onsubmit="return ReadForm(this, true);"><input type="submit" value="Add to Cart" /><input type="hidden" name="product" value="CISSP Review Notes Package" /><input type="hidden" name="price" value="25.00" /><input type="hidden" name="product_tmp" value="CISSP Review Notes Package" /><input type="hidden" name="addcart" value="1" /></form></object></strong></p>
<p style="text-align: center;" align="center">All Purchases are securely processed through Paypal. Once you click the button please check your shopping cart at the upper right hand side of the page to complete your order.</p>
<p style="text-align: center;" align="center"><strong>IMPORTANT NOTICE: </strong></p>
<p style="text-align: center;" align="center">I  MANUALLY REVIEW ALL ORDERS. SO ONCE YOU PURCHASE THE PRODUCT, THERE  WILL BE SOME DELAY ON YOU RECEIVING AN E-MAIL FROM ME WITH THE LINK TO  THE DOWNLOAD AREA OF THE PRODUCT. YOU WILL GET A RESPONSE FROM ME  WITHIN 24-48 HOURS.</p>
</td>
</tr>
</tbody>
</table>
<p><!--End CISSP ebook ad--></p>
<p>A popular method is using source-routed IP packets. This allows a hacker at point A on the network to participate in a conversation between B and C by encouraging the IP packets to pass through its machine.</p>
<p>If source-routing is turned off, the hacker can use &#8220;blind&#8221; hijacking, whereby it guesses the responses of the two machines. Thus, the hacker can send a command, but can never see the response. However, a common command would be to set a password allowing access from somewhere else on the net.</p>
<p>A hacker can also be &#8220;inline&#8221; between B and C using a sniffing program to watch the conversation. This is known as a &#8220;man-in-the-middle attack&#8221;.</p>
<p>A common component of such an attack is to execute a denial-of-service (DoS) attack against one end-point to stop it from responding. This attack can be either against the machine to force it to crash, or against the network connection to force heavy packet loss. (Source: <a href="http://en.wikipedia.org/wiki/Session_hijacking" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Session_hijacking?referer=');">http://en.wikipedia.org/wiki/Session_hijacking</a>).</p>
<p><strong>Common Session Hijacking Attacks</strong></p>
<ul>
<li>IP Spoofing<strong> </strong>
<ul>
<li>Used to convince a system that it is       communication with a known entity that gives an intruder access<strong> </strong></li>
<li>Involves altering the packet at the TCP level<strong> </strong></li>
<li>The attacker sends a packet with an IP source       address of a known, trusted source<strong> </strong></li>
</ul>
</li>
<li>E-mail Spoofing<strong> </strong>
<ul>
<li>The forgery of an e-mail header so that the       message appears to have originated from someone or somewhere other than       the actual source<strong> </strong></li>
</ul>
</li>
<li>TCP Sequence Number<strong> </strong>
<ul>
<li>Tricks the target in believing that it’s       connected to a trusted host and then hijacks the session by predicting       the target’s choice of an initial TCP sequence number<strong></strong></li>
<li>Used to launch various other attacks on other       hosts<strong></strong></li>
</ul>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.trehb101.com/index.php/2009/12/11/cissp-exam-note-domain-2-telecommunications-and-networking-security-%e2%80%93-session-hijacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

