|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: sessions and connections> But you don't need to authenticate & negotiate parameters for > all the connections in the session or do you? > Isn't the leading connection sufficient... NO!! The IP addresses don't have to be the same for connections in a session. If subsequent connections aren't authenticated, an attacker waits for the first connection to establish, adds his connection to the Target to the session and sends a format command ... Some of the negotiated parameters can only be negotiated on the leading connection and are indicated as such in the draft. Thanks, --David --------------------------------------------------- David L. Black, Senior Technologist EMC Corporation, 42 South St., Hopkinton, MA 01748 +1 (508) 249-6449 *NEW* FAX: +1 (508) 497-8500 black_david@emc.com Mobile: +1 (978) 394-7754 ---------------------------------------------------
Home Last updated: Wed Dec 19 20:17:51 2001 8153 messages in chronological order |