From owner-freebsd-questions@FreeBSD.ORG Mon Oct 18 02:52:57 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 163FD106566C for ; Mon, 18 Oct 2010 02:52:57 +0000 (UTC) (envelope-from cyberleo@cyberleo.net) Received: from paka.cyberleo.net (paka.cyberleo.net [66.219.31.21]) by mx1.freebsd.org (Postfix) with ESMTP id DB5798FC17 for ; Mon, 18 Oct 2010 02:52:56 +0000 (UTC) Received: from [172.16.44.4] (den.cyberleo.net [66.253.36.39]) by paka.cyberleo.net (Postfix) with ESMTPSA id 60C35295FF; Sun, 17 Oct 2010 22:52:55 -0400 (EDT) Message-ID: <4CBBB686.6000100@cyberleo.net> Date: Sun, 17 Oct 2010 21:52:54 -0500 From: CyberLeo Kitsana User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.9) Gecko/20100911 Lightning/1.0b3pre Thunderbird/3.1.3 MIME-Version: 1.0 To: Brandon Gooch References: <201010171718.o9HHISJq003050@mail.r-bonomi.com> In-Reply-To: X-Enigmail-Version: 1.1.1 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: Robert Bonomi , freebsd-questions@freebsd.org, Nerius Landys Subject: Re: UDP packet spoofed LAN source address? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Oct 2010 02:52:57 -0000 On 10/17/2010 06:37 PM, Brandon Gooch wrote: > On Sun, Oct 17, 2010 at 4:59 PM, Nerius Landys wrote: >>> >>> >>>> Maybe, is there a simple 10 line C program that I can run and compile to >>>> check if this scenario is possible on _my_ server? >>> >>> 'netcat' has the capability built in. >>> >>> >> root# echo "hi" | nc -u -w 1 -p 30002 -s 64.156.193.115 daffy 30001 >> nc: bind failed: Can't assign requested address >> >> I don't seem to be able to spoof a source address using netcat, unless I'm >> missing something in the man page. > > I think you need to have the IP address you wish to spoof bound to an interface. Or use Nemesis as root. [0] http://nemesis.sourceforge.net/ -- Fuzzy love, -CyberLeo Technical Administrator CyberLeo.Net Webhosting http://www.CyberLeo.Net Furry Peace! - http://wwww.fur.com/peace/