Advanced | Help | Encyclopedia
Directory


Reflection attack

A reflection attack is a potential way of attacking a challenge-response authentication system which uses the same protocol in both directions. The attacker initiates two separate connection attempts to the same target, and sends back the challenges received on one connection as its responses on the second connection. If the authentication protocol is not carefully designed, it will accept its own responses as valid, thereby leaving the attacker with one fully-authenticated channel connection (the other one is simply abandoned).

For more details, see Computer Networks 4th ed by Andrew S Tanenbaum, ISBN 0–13–038488–7, pages 787–790.








Links: Addme | Keyword Research | Paid Inclusion | Femail | Software | Completive Intelligence

Add URL | About Slider | FREE Slider Toolbar - Simply Amazing
Copyright © 2000-2008 Slider.com. All rights reserved.
Content is distributed under the GNU Free Documentation License.