Small Business Resources, Business Advice and Forms from AllBusiness.com

CA-2001-09: Statistical weaknesses in TCP/IP initial sequence numbers.(Transmission Control...

Systems Affected: Systems using TCP stacks which have not incorporated RFC1948 or equivalent improvements; systems not using cryptographically secure network protocols such as IPSec.

Overview: Attacks against TCP initial sequence number (ISN) generation have been discussed for some time now. The reality of such attacks led to the widespread use of pseudo-random number generators (PRNGs) to introduce some randomness when producing ISNs used in TCP connections. Previous implementation defects in PRNGs led to predictable ISNs despite some efforts to obscure them. The defec

In addition, make sure to read these premium articles also available with your free trial: