arXiv · 1807.08026
TCP SYN Cookie Vulnerability
Abstract
TCP SYN Cookies were implemented to mitigate against DoS attacks. It ensured that the server did not have to store any information for half-open connections. A SYN cookie contains all information required by the server to know the request is valid. However, the usage of these cookies introduces a vulnerability that allows an attacker to guess the initial sequence number and use that to spoof a connection or plant false logs.
Explore related subjects
Keep this discovery
Dakshil Shah, Varshali Kumar. 2018-07-20. TCP SYN Cookie Vulnerability. https://arxiv.org/abs/1807.08026
Cite the original work for its findings. Save a collection to share your selection of sources.