No , the attacker does not need to know what the initial SYN value is to complete the handshake of TCP 3. Also, for any port, tcp cannot be in the half-open state when they use SYN cookies. The answer lies in cryptography.
SYN Cookies Implementation May Use Symmetric Cipher . , , TCP. SYN , , IP- , IP- . SYN, , , "" tcp- (at- DoS). , SYN-ACK, SYN. SYN-ACK, , IP- , IP- .
Mikey source
share