7 hours ago
- The Idle scan was conceived in late 1998 by the author after moving to Milan.
- The author created Hping, a tool for crafting custom TCP/IP packets, which led to the discovery of the incrementing IP ID field.
- The incrementing IP ID field was a known but neglected vulnerability that could leak information about a host's outgoing traffic.
- Discussions with Lorenzo Cavallaro helped refine the idea, and after modifying Hping, the attack was successfully tested.
- The attack was announced in a drunken email to BUGTRAQ, originally called 'dumb host scan' but later renamed 'Idle scan'.
- The Idle scan became a classic attack in cybersecurity history.