HERT Advisory #3 - The way FreeBSD handles random sequence number incrementing is weak. With 3 consecutive random increments captured from the responses of 4 SYN packets sent to the target, an attacker can rebuild the random state of the remote machine, and predict the next sequence number. Includes proof of concept code.
20474d64094f221403303da1368bc9aahert.00001.solaris.lpstat
272dcee4474c7eef9810bc8273c33dcfhert.0002.lsof.4-40
4f3cc0882eba9d5a213965cb352c14ee