What can an attacker accomplish with a forged source address when no reply ever comes back?
answer
- the effect must land on arrival
- the answer goes to somebody else
- no round trip, so no session
- an unpredictable 32-bit number to guess
- position, not skill, is the prerequisite
basics
~10 sOnly attacks whose effect lands on arrival: single-datagram commands, floods that consume state at the target, and provoking a third party into answering the forged address. Anything needing something back is out of reach.
solid answer
~50 sForging a source address makes the attacker blind: whatever the target sends goes to the address that was claimed, not to them. That splits the attack surface cleanly. Reachable are effects that complete when the packet arrives — a connectionless command that changes state, a flood of connection attempts that ties up resources, or making some service direct its answer at the address you forged. Out of reach is anything requiring a round trip: an attacker cannot complete a TCP handshake off-path, because the answer carrying the server's randomly chosen initial sequence number goes to the real owner of that address, which replies with a reset and tears the half-open connection down. No handshake means no session, no authentication challenge answered, no data read back, no foothold and no persistence. That is why this is the lowest-capability technique in the whole category: the scarce ingredient is a network willing to forward the forged packet, and that is rented rather than earned.
go deeper
Remember the single rule that generates every answer here: the reply goes to the address that was written, so the attacker gets nothing back.
Be able to sort attacks into reachable and unreachable from that one constraint, and to explain why a three-way handshake defeats an off-path forger.
Show that you ask where the attacker is standing before judging the risk, since an on-path position removes the constraint entirely and changes the answer.
Frame the exposure in supply terms: the technique is priced by how many networks will forward a forged packet, not by how hard any individual target is.
## Blindness is the defining constraint The interesting thing about source forgery is not that it is possible; it is what it costs you. The moment you write somebody else's address into the source field, you give up receiving anything the target sends. Every answer is delivered to the address you claimed. You are shouting into a room you cannot hear. That single constraint decides which attacks are available, and it is the reason this technique sits at the bottom of the capability ladder rather than the top. ## What survives the constraint **Effects that land on arrival.** Some protocols act the moment a datagram shows up. A connectionless management or control message that changes a setting, appends an entry, or triggers an operation has already succeeded before any answer would have been generated. The attacker does not care where the acknowledgement went — the state change is done. **Resource consumption at the target.** A flood of connection openings costs the target memory and table space for every half-open entry, and none of that requires the attacker to complete anything. Forging the sources also spreads the apparent origin across the whole address space, which is a side benefit rather than the point. **Making a third party speak to the forged address.** Any service that answers unsolicited requests can be made to answer *someone else*, simply by claiming that someone else's address. The attacker never sees the answer, which is exactly the intent: the answer is the payload, and it is aimed at whoever was named. ## What does not survive it **A TCP session, from off-path.** The three-way handshake exists partly to prove that the peer can receive at the address it claims. The server answers a SYN with a SYN-ACK containing an initial sequence number it chose, and the client must echo an acknowledgement derived from it. A forger never sees that number. Modern stacks choose initial sequence numbers unpredictably rather than from a simple counter, so guessing means hitting a 32-bit value inside a narrow window. Worse for the attacker, the real owner of the forged address receives a SYN-ACK for a connection it never opened and answers with a reset, which collapses the half-open state on the server. Blind session hijacking of a modern stack from off-path is a museum piece, not a technique. **Anything with a challenge.** If the protocol sends a nonce, a cookie, a ticket or a random value that must be returned, the forger is finished — the challenge went to somebody else. **Anything that returns data.** There is no exfiltration path, because the data is delivered to the address claimed. There is no reconnaissance either, in the sense of learning the answer, because the answer is not yours. **Anything persistent.** No session means no foothold, no account, no lateral movement, no persistence. The whole attack begins and ends with packets leaving. ## The economics, which are the real teaching point Because the technique requires no interaction, it also requires almost no skill. Constructing a packet with an arbitrary source field is a solved problem published in tutorials and proof-of-concept code, and the low-end market has packaged it into subscription flooding services aimed at people who cannot write any of it. The actor most likely to use it is the least sophisticated one in the category. What makes it possible is not the attacker's capability but a supply-side fact: somewhere in the world there are networks that will forward a customer's packet no matter what source it carries. The forger's only real prerequisite is access to one of them. This is worth saying out loud in an interview, because it reframes the whole problem — the technique cannot be made harder by hardening targets, only by shrinking the set of networks from which a forged packet can be emitted. ## Position changes everything Every limit above assumes the attacker is off-path: unable to observe traffic destined for the address they are claiming. An attacker who *can* observe that traffic is not blind at all, and the constraint disappears entirely — the forgery becomes session-capable, because they can read the answers meant for the address they claimed. So the one-way limit is a property of where the attacker sits, not of the technique. When you are asked whether spoofing is dangerous, the correct first question back is where the attacker is standing.
- Why does an off-path attacker fail to complete a spoofed TCP connection?The server's SYN-ACK is addressed to the forged source, so the attacker never learns the initial sequence number it must acknowledge, and modern stacks pick that number unpredictably rather than from a counter. On top of that, the real owner of the address receives an unsolicited SYN-ACK and answers with a reset, which destroys the half-open state.
- Does the one-way limit still hold if the attacker can observe traffic to the forged address?No — it collapses. The limit exists only because answers are delivered somewhere the attacker cannot read. Someone positioned to see traffic destined for the claimed address gets the round trip back and can hold a session. When judging spoofing risk, always establish where the attacker sits before deciding what they can do.
- Why is this technique associated with low-skill attackers rather than sophisticated ones?Because there is nothing to learn. Writing an arbitrary value into a header field is published, packaged and rentable, and the attack needs no interaction, no target knowledge and no follow-through. The genuinely scarce resource is a network that will forward the packet, and that is bought rather than built.
saying these in an interview costs you the question
- Claims spoofing lets an attacker log in to a service
- Thinks blind TCP session hijacking is routine today
- Says the attacker reads the responses to forged packets
- Assumes the technique requires advanced capability