Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. SQL Server
  3. Question
SQL Server

Can I use a TCP Injection for my existing connection?

Asked by Anisha Dalal Jan 11, 2022 372 views 1 answer
Share

About this question

I read two cases regarding the TCP connection and I have a question for each case -The first oneThe H has an established TCP connection: C = (210.10.10.10,9999,98.98.98.98,9999). That connection is used for HTTP communication- let's assume that some HTTP frames are sent by the connection C.

So, H just sends some HTTP messages.

Now, MH would like to send a HTTP message on behalf of H. So, it guesses TCP.SequenceNumber and other TCP's header fields. Then MH sends a proper TCP message with IP.srcAddress set toH` 's address and HTTP's message: 'I am a fool' (look at scheme).

A packet was received as the next packet in connection C.

My question is: Is it a possible scenario? The second one

The situation is the same as above. However, H and Server communicate by https. MH tries to send a HTTP message, as before. It cannot be encrypted because MH does not know a key. So, it cannot be correctly decrypted by a server. Server can find out that a packet is malicious because the content is not decrypted to the correct form.

Is it the only symptom that the packet is malicious? It seems to be slippery.

Your answer

1 Answer

More SQL Server discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest SQL Server Blogs

Guides, tips and career advice on SQL Server from JanBask experts.