Furto di sessione TCP (TCP session hijacking) Roube de sessão TCP (TCP sessão  hijacking) TCP Session Hijacking Vol de session TCP (TCP session hijacking) Secuestro de sesión TCP

TCP session hijacking

"TCP session hijacking" is a technique that involves intercepting a TCP session initiated between two machines in order to hijack it.

In that the authentication check is performed only when opening the session, a pirate who successfully launches this attack is able to take control of the connection throughout the duration of the session.

Source routing

The initial hijacking method used involved using the source routing option of the IP protocol. This option made it possible to specify the path IP packets were to follow, using a series of IP addresses showing the routers to be used.

By exploiting this option, the pirate could indicate a return path for packets to a router under his control.

Blind attack

When source routing is disabled, which is the case nowadays for most equipment, a second method involves sending packets as "blind attacks", without receiving a response, by trying to predict sequence numbers.

Man in the middle

Also, when the pirate is on the same network thread as his two contacts, he can monitor the network and "quiet" one of the participants by crashing his machine or by flooding the network to take his place.

More information



Last update on Thursday October 16, 2008 02:43:15 PM.This document entitled « TCP session hijacking » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Best answers for « TCP session hijacking » in :
Man in the middle attack Show Session hijacking attack The "session hijacking" attack involves redirecting data intended for a target machine to the hijacker's machine, giving him access to information he is not supposed to have.
TCP/IP Show What does TCP/IP mean? TCP/IP is a suite of protocols. The acronym TCP/IP means "Transmission Control Protocol/Internet Protocol" and is pronounced "T-C-P-I-P". It comes from the names of the two major protocols in the suite of protocols, i.e....
Port/Ports TCP/IP Show The use of ports Many TCP/IP programs can be executed simultaneously over the Internet (you can for example open several browsers simultaneously or browse HTML pages while downloading a file via FTP). Each of these programs works with a protocol,...
Lock your Windows XP session ShowLock your Windows XP session Method 1: Shortcut Method 2: Using DOS Method 3: Create a .bat file There are several ways available to be able to lock your Windows XP (including Home Edition and XP Pro) Method 1: Shortcut 1....
Differences between the UDP and TCP protocols ShowDifferences between the UDP and TCP protocols User Datagram Protocol (UDP) Transmission Control Protocol (TCP) User Datagram Protocol (UDP) It is part of the base protocols of the Internet Protocol Suite. Programs on networked...
Save settings on closing up Windows session ShowSave settings on closing up Windows session For the professional versions For Home edition Here below is a small tip on how to save automatically your settings when exiting a Windows session. System requirements: Windows 2000 to...
Download Hijackthis ShowHijackthis is a software which helps to scan, however, it is not to be put in all the hands. It is a specific tool allowing to detect and to delete spywares and hijackers installed in secret on your computer. It also allows to increase the...
Download Advanced TCP IP Data Logger ShowDescription: Advanced TCP/IP Data Logger will help you in your daily technical needs. You will be able to get information about your network and any device that is connected to it in real time. Features: You can send and receive serial data...
TCP protocol ShowThe characteristics of TCP protocol TCP (which means Transmission Control Protocol) is one of the main protocols of the transport layer of the TCP/IP model. It makes it possible, at application level, to manage data coming from (or going to) the...
Session keys ShowAdvantages of a session key Asymmetric algorithms (which come into play in public-key cryptosystems) make it possible to eliminate problems related to key sharing via a secure channel. However, they remain much less effective (in terms of...
Messaging protocols (SMTP,POP3 and IMAP4) ShowIntroduction to e-mail E-mail is considered as being the most widely used service on the Internet. So the TCP/IP protocol suite offers a range of protocols allowing the easy management of email routing over the network. The SMTP protocol The...