You can use something like Hunt to do TCP session hijacking from the local network, but there are limitations to how well it works. Usually you will get to send one communication to the server before an ACK storm occurs - unless you can somehow prevent ACKS from the server for data you sent getting to the original client.
Try it out and report back with your results, I'd be curious to know how you go.



