Hello, Can someone help to figure out what methods to use to find ip address of the person implementing the teardrop attack and the ip address of the one who is being attacked? Also, how would I figure out the byte numbers that are being replaced by the teardrop attack. The capture that I am using is the sample teardrop that is found from wiki wireshark; http://wiki.wireshark.org/SampleCaptures?action=AttachFile&do=view&target=teardrop.cap. Any help would be great. Thanks! asked 09 Feb '12, 22:07 Jason007 edited 26 Feb '12, 20:41 cmaynard ♦♦ |