Certified Ethical Hacker – CEH – 312-50 – Question282

You are attempting to man-in-the-middle a session. Which protocol will allow you to guess a sequence number?


A.
TCP
B. UPD
C. ICMP
D. UPX

Correct Answer: A

Explanation:

At the establishment of a TCP session the client starts by sending a SYN-packet (SYN=synchronize) with a sequence number. To hijack a session it is required to send a packet with a right seq-number, otherwise they are dropped.

References: https://www.exploit-db.com/papers/13587/