"Cryptanalysis" of these X-Trace ?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


sci.crypt archive

"Cryptanalysis" of these X-Trace ?

From: Francois Grieu <fgrieu@francenet.fr>
Date: Mon Feb 06 2006 - 08:00:34 CET

Apparently the perp of the "cancel" attack on sci.crypt has moved
to another proxy. One recent cancel is copied below, followed by
the X-Trace field in some of >1200 similar cancels. How do we read
the X-Trace field ?

Note: last byte in X-Trace seems to be 0xF4

More cypertext is at
http://mpqs.free.fr/ciphertext.zip

Repetition being the essence of Usenet:

This newsgroup, sci.crypt, is again under attack.
It received thousands systematic "cancel" messages.
When reading the group thru a server that honors these
cancels, the canceled messages do not show.

To survive this, my strategy is to read messages thru an
open nntp server that ignores the rogue cancels:
nntp://nntp.cquest.utoronto.ca/sci.crypt

and post messages (e.g. this one) using my usual ISP's
nntp server.

Given the ongoing counterstrike of REPOST, based on
earlier experience, I suggest killing these with
@news.noc.cabal.int   in the  Message-ID  header
and making sure to NOT include the word REPOST in the
title of a reply message.

An alternative would be to use an nntp server that filters
unwanted cancels and maybe the corresponding reposts; but
these are commercial.

   François Grieu

Path: news.free.fr!xref-2.proxad.net!spooler3-2.proxad.net!infeed-1.proxad.net!proxad.net!198.186.190.250.MISMATCH!news-pusher.readnews.com!198.186.190.247.MISMATCH!news-out.readnews.com!news-xxxfer.readnews.com!hwmnpeer01.lga!hwmedia!news.highwinds-media.com!hw-filter.lga!fe04.lga.POSTED!53ab2750!not-for-mail
From: "Abhi" <abhilashverma@gmail.com>
Control: cancel <1139116002.403429.63400@f14g2000cwb.googlegroups.com>
Subject: Cancel "Setting TCP flags on OpenSSL packets"
Newsgroups: sci.crypt
Message-ID: <6150148666.080004.33237@f14g2000cwb.googlegroups.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Mailer: Mozilla 4.76 [en] (Win98; U)
Lines: 2
X-Trace: badccedimaighclepiccoklfphijobmlkgdeijciigecclloaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchejghojpeahjbeodaladjongclhmjjbeogohjÙ
NNTP-Posting-Date: Sat, 04 Feb 2006 22:07:22 MST
Date: Sun, 5 Feb 2006 02:52:44 GMT

This message was cancelled from within Mozilla.

X-Trace: badccedimaighclecidkkbanibjkdllcaeebgcfdhijmhanhaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchpfiejknepenbnhglfjnmklcjebnhmhkakpjiÙ
X-Trace: badccedimaighclecidkkbanibjkdllcfpgakppaeihmfekeaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchopnaeookgnppankmjaggkhgkmadggaomkpjiÙ
X-Trace: badccedimaighclecidkkbanibjkdllcahombafgkcjcphikaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchopnaeookgnppankmllkiclbachpnmnflkpjiÙ
X-Trace: badccedimaighclecidkkbanibjkdllcafckfkcbakpellhoaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchopnaeookgnppankmnioahbmjomjapkiekpjiÙ
X-Trace: badccedimaighcledjfhajeojlfcceokjnfafnbimgbcimeeaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchgjafhinokekbhfioihibdkpbjkjnbnhelacaÙ
X-Trace: badccedimaighcledjfhajeojlfcceokmgidoglecaecabplaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchgjafhinokekbhfiojbbadbkpiceemjialacaÙ
X-Trace: badccedimaighclecidkkbanibjkdllchdhknajlcaejhnpoaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchlnlhlckjgdnjnhkfabopeihbmejflolblacaÙ
X-Trace: badccedimaighcledjfhajeojlfcceokpfcjineobjbnfnecaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchledbkiindgmgomgjnjflefllgjjhgkjelacaÙ
X-Trace: badccedimaighcledjfhajeojlfcceokmegccapocgclnmifaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchighhfigjknidhoflekecjdahmlkkcimglacaÙ
X-Trace: badccedimaighcledjfhajeojlfcceokddkgpfhbjgedholmaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchdechmmkcnfemdjgokmlpfbhgfcocnaholacaÙ
X-Trace: badccedimaighclecidkkbanibjkdllconegncojahhdebdcaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchgjafhinokekbhfiolgjghklegchhgnkhlacaÙ
X-Trace: badccedimaighcledjfhajeojlfcceokekihabmhphfjhdapaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchighhfigjknidhoflcglohifdnimihnpllacaÙ
X-Trace: badccedimaighcledhejikkoboohkidpbjfhenkefplmadhnaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchhggendpgbmflnlhjlbfcjhidanddnjpeepopÙ
X-Trace: badccedimaighcledhejikkoboohkidppimcnnicofdfonjaaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchaagageigaiojjjcmgcpmlpolilelfaihepopÙ
X-Trace: badccedimaighcleckobhlodddklpjlhjmmchandlbbeigbkaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchkofamnkakjjdjhagmindmeehndjdanbdkoagÙ
X-Trace: badccedimaighcleckobhlodddklpjlhekmlaiehbkcpgjbfaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchofbnagicgonlogmfchidpehfamabmcpjkoagÙ
X-Trace: badccedimaighclepiccoklfphijobmlkgdeijciigecclloaoepldjomgkghmlaebbdokmcigmdjfonecojabbfckobgkchejghojpeahjbeodaladjongclhmjjbeogohjÙ
Received on Tue Feb 7 21:00:03 2006