In a nutshell, given IP spoofing, in order to hijack a TCP connection they need to work out the sequence number. They take advantage of a firewall that throws away invalid sequence numbers to pervert it into a device that reveals the valid sequence number.
It hinges on knowing if a packet was tossed or not. They do this with either a TTL that will expire between the firewall and destination, or by an unprivileged conspirator program on the target device (e.g. watching the linux packet counters on an android phone).
They apparently have success with about one third of the mobile carriers they have tried.
It hinges on knowing if a packet was tossed or not. They do this with either a TTL that will expire between the firewall and destination, or by an unprivileged conspirator program on the target device (e.g. watching the linux packet counters on an android phone).
They apparently have success with about one third of the mobile carriers they have tried.