tcp/routing question...

Scot L. Harris webid at cfl.rr.com
Tue Jun 7 15:24:49 UTC 2005


On Tue, 2005-06-07 at 10:45, bruce wrote:
> hi..
> 
> question.. is there a way for me, as the person running a server, able to
> determine the actual ip address of the client that i'm talking to. or is it
> seriously easy for a client (man in the middle) to spoof the ip address. in
> which case you can never be completely sure as to who you're talking to...
> 
> thanks

Man in the middle attacks are relatively difficult.  This is due to the
need for the attacker to take control of specific nodes in the path your
traffic is taking through the network.  This normally means getting
control of or inserting a device between your system and a router that
is near your system.  

It is doable but non-trivial.

-- 
Scot L. Harris
webid at cfl.rr.com

The amount of time between slipping on the peel and landing on the
pavement is precisely 1 bananosecond. 




More information about the users mailing list