IP Spoofing in XP and 2000?
IP Spoofing in XP and 2000?
I know that the IP spoofing will be done through Raw Sockets/Packets but how exactly do you use this to spoof your IP. I would figure it is not a option right in windows itself.
I think I've done enough conventions to know how to spell Melllvar.
learn??...hey dude that post wasn't meant to flame you, don't be fooled by the nickname newbie69 or the little posts i have, that post was meant for the people that were going to flame you for being a script kiddie and all that, a way misunderstanding there, and spoofing is in the category "hacking" , there you learned something (hacking isnt discussed here meaning not in speedguide.net or in there forums), i use *nix flavors too (has more ip spoofing .c programs for you to compile), and i never said anything about me not learning, so don't say that im not trying to learn
and if i knew i WOULD tell you!!!
I'm not much of a windows user, again don't be fooled by the "newbie69" nickname
it would be quite fascinating to know how to do it on xp
and if i knew i WOULD tell you!!!
I'm not much of a windows user, again don't be fooled by the "newbie69" nickname
it would be quite fascinating to know how to do it on xp
- Juggernaut
- Senior Member
- Posts: 1645
- Joined: Fri Aug 11, 2000 12:00 am
- Location: Parts Unknown
Whats that mean
why the hell does everyone think the sig is serious its a damn joke and I dont know everything just asking a question. Didnt get what he was getting accross now I do. Sorry for having sig ges.
I think I've done enough conventions to know how to spell Melllvar.
- W_I_Z_K_I_D
- Regular Member
- Posts: 363
- Joined: Sun Jun 10, 2001 9:33 am
- Location: !!!Your Computer-You Just Dont Know It YeT!!!
Yo mR Trix or whateva your name is
Mr newbie was coolin it down man bein nice and sh*it
And you flame back , whas this man your in a security furum.
As for your question i dunno

Mr newbie was coolin it down man bein nice and sh*it
And you flame back , whas this man your in a security furum.
As for your question i dunno
!!!What Man Can Make
Man Can Brake!!!
Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM
** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner
Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
Man Can Brake!!!
Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM
** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner
Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
- W_I_Z_K_I_D
- Regular Member
- Posts: 363
- Joined: Sun Jun 10, 2001 9:33 am
- Location: !!!Your Computer-You Just Dont Know It YeT!!!
so what ya sayin
you stupid or something..?
you stupid or something..?
!!!What Man Can Make
Man Can Brake!!!
Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM
** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner
Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
Man Can Brake!!!
Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM
** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner
Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
packet creation is simple.......you just hav to have the resources for it.
Most people spoof packets for stress testing different applications abilitie to handle requests from null addresses.
If you want a packet creator for windows 2000/nt low-level network packets check out my web site and look under the "security tools" in the download section.
Have Fun
Most people spoof packets for stress testing different applications abilitie to handle requests from null addresses.
If you want a packet creator for windows 2000/nt low-level network packets check out my web site and look under the "security tools" in the download section.
Have Fun
http://www.computerglitch.net"I'm doing a (free) operating system (just a hobby, won't be big and professional...) for AT clones... It's not portable and it probably [won't ever] support anything other than AT hard disks, as thats all I have :-(." --Posted on Usenet August 1991 by Linus Trovalds
curiosity builds security | dd if=/dev/zero of=/dev/hda bs=512 count=100
EOF
Well since Microsoft adopted much of the FreeBSD TCP/IP stack in both windows 2000 and windows XP it makes since that raw sockets would be available in the OS.
Personally I don't see what the big deal is, it isn't the os that is causing problems with spoofing, it is the ISPS. If ISPs correctly configured routers and firewalls end user spoofing would be impossible regardless of the os.
Its not big deal and its been expected for a while now, if anything it will just cause some uniformed network admins to get a crash course on how to actually configure a router.
Personally I don't see what the big deal is, it isn't the os that is causing problems with spoofing, it is the ISPS. If ISPs correctly configured routers and firewalls end user spoofing would be impossible regardless of the os.
Its not big deal and its been expected for a while now, if anything it will just cause some uniformed network admins to get a crash course on how to actually configure a router.
Cisco Certified Network Professional
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
Protection must come from the ISP level for this issue, protection from the OS level wont work because of the multitude of operating systems that support sockets and the ease of creation of data packets.
Another example is smurf, if routers and networks were properly configured smurf would not be an issue. With the increased litagation involving the Internet it is entirely possible that the courts will find an ISP responsible for damages when an attack originates on their network which could have been prevented if they had properly configured it.
To prevent the majority of spoofing all they need to do is configure an access list on the router. It would still allow spoofed addresses in their ip block but the majority of people want to spoof non local ip addresses and this also can be blocked.
It doesn't cost anything to configure it correctly and we will continue to see these problems until it is in the ISPs best interest to implement these simple rules (most the big ones already do, its the smaller ones that cause the problems).
Asking Microsoft to prevent ddos or dos attacks is not feasible or viable, it is like trying to create a river dam with one branch.
Another example is smurf, if routers and networks were properly configured smurf would not be an issue. With the increased litagation involving the Internet it is entirely possible that the courts will find an ISP responsible for damages when an attack originates on their network which could have been prevented if they had properly configured it.
To prevent the majority of spoofing all they need to do is configure an access list on the router. It would still allow spoofed addresses in their ip block but the majority of people want to spoof non local ip addresses and this also can be blocked.
It doesn't cost anything to configure it correctly and we will continue to see these problems until it is in the ISPs best interest to implement these simple rules (most the big ones already do, its the smaller ones that cause the problems).
Asking Microsoft to prevent ddos or dos attacks is not feasible or viable, it is like trying to create a river dam with one branch.
Cisco Certified Network Professional
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
- Stef
- Advanced Member
- Posts: 712
- Joined: Sun Apr 16, 2000 12:00 am
- Location: Edmonton, Alberta, Canada
Hey guys, interresting thread! I though that I would drop off a link that describes several configuration techniqes on preventing various types of DoS attacks.
Of course, the document decribes several configuration tips of the best routers and network operating systems.
You'll notice Windows NT is not on the list
I've been running Linux for a one year now. I've always been using some of the advanced Linux kernel IP stack options and my system has nerver crashed from any DoS attack or malformed datagrams.
The worse thing that has ever happened to me from a DoS attack is that I had to bring one ethernet interface down. Plug my DSL modem into another ethernet device. Then re-initialize the device and request a new DHCP lease. All this without a reboot :-D
If you have a router or are running UNIX at home, read this document and prevent your multihomed host from becoming a hazard to your network and to the internet!!
Minimizing Denial of Sevice Attacks
Stef
Of course, the document decribes several configuration tips of the best routers and network operating systems.
You'll notice Windows NT is not on the list
I've been running Linux for a one year now. I've always been using some of the advanced Linux kernel IP stack options and my system has nerver crashed from any DoS attack or malformed datagrams.
The worse thing that has ever happened to me from a DoS attack is that I had to bring one ethernet interface down. Plug my DSL modem into another ethernet device. Then re-initialize the device and request a new DHCP lease. All this without a reboot :-D
If you have a router or are running UNIX at home, read this document and prevent your multihomed host from becoming a hazard to your network and to the internet!!
Minimizing Denial of Sevice Attacks
Stef
Good to know my topic is doing well and in case my question wasnt totaly clear I only want to manipulate the packets being sent out to "spoof" my IP for Protection. Because I go on mIRC alot and my IP gets picked on alot by some guys I pissed off once so if I could switch it they would not be able to attack me anymore and I could get a chance to actually ask them why they do it.
I think I've done enough conventions to know how to spell Melllvar.
Spoofing wouldn't help you with IRC, in fact it has no real useful purpose for the average user.
The reason spoofing would not work for you is the source ip address is faked so all reply traffic is sent to that fake source ip address, that means that you would not be able to establish a connection with any servers because you will not see the replies to the packets you are sending.
There used to be a way to make your ip resolve to a different hostname but that didn't protect you because you could still be nuked. (and this vunerability has long since been fixed).
Pretty much if you are worried about security either run Unix or get a good firewall like conseal pc firewall and spend some time configuring it.
IP spoofing is still used in attacks because for most attacks you don't need to see the reply, so really raw sockets in xp and 2000 are still no big deal.
I wouldn't be surprised if they limited them to the people with administrator access like Unix but then again I wouldn't be too surprised if they didn't either..
The reason spoofing would not work for you is the source ip address is faked so all reply traffic is sent to that fake source ip address, that means that you would not be able to establish a connection with any servers because you will not see the replies to the packets you are sending.
There used to be a way to make your ip resolve to a different hostname but that didn't protect you because you could still be nuked. (and this vunerability has long since been fixed).
Pretty much if you are worried about security either run Unix or get a good firewall like conseal pc firewall and spend some time configuring it.
IP spoofing is still used in attacks because for most attacks you don't need to see the reply, so really raw sockets in xp and 2000 are still no big deal.
I wouldn't be surprised if they limited them to the people with administrator access like Unix but then again I wouldn't be too surprised if they didn't either..
Cisco Certified Network Professional
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
Microsoft Certified Systems Engineer
FreeBSD - The Power To Serve
