top bar
QuickTopic free message boards logo
Skip to Messages

TOPIC:

Wild-ass TCP tools

2
Dan KaminskyPerson was signed in when posted
11-19-2002
10:53 AM ET (US)
Justin --

bash-2.05a# phentropy
Source of entropy required.
phentropy 1.0: Zalewskian Phase Space Entropy Viz for OpenQVIS

I take no credit :-) I just wrote a bit of glue for other people to sniff...

--Dan
1
Justin MasonPerson was signed in when posted
11-19-2002
09:16 AM ET (US)
Wotcher,

been looking at this stuff myself a little recently for
SpamAssassin -- I'm analysing "random" fields in forged spam
Message-IDs for characteristic patterns.

The technique is not new -- these are the original papers:

Strange Attractors and TCP/IP Sequence Number Analysis:
http://razor.bindview.com/publish/papers/tcpseq.html

Strange Attractors and TCP/IP Sequence Number Analysis - One
Year Later: http://lcamtuf.coredump.cx/newtcp/

But Dan's pictures are much, much nicer ;)
Upgrade to PRO

Upload pictures, personalize your board, and more!

Print | RSS Views: 371 (Unique: 296 ) / Subscribers: 1 | What's this?