Great Circle Associates Firewalls
(February 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Pentagon displays due respect for hackers
From: Darrell Fuhriman <darrell @ teleport . com>
Date: Wed, 28 Feb 1996 10:59:41 -0800 (PST)
To: Sick Puppy <sikpuppy @ maestro . com>
Cc: firewalls @ greatcircle . com

> > ... ip fragmentation attacks,
> 
> Wozzat?

Fragment the IP packet so the address are in different packets, as well as
the port number.  The router can't buffer them, and can't filter
them until it knows all the information.  So, it lets them through.  And
since most firewalls only block on the SYN... tada.. open connection.

Darrell Fuhriman
Teleport System Administration


Follow-Ups:
Indexed By Date Previous: Re: VPN's over the internet
From: Adam Safier <asafier @ explorer . csc . com>
Next: Re: Proxy-server for AOL client???
From: Perry The Cynic <perry @ sutr . cynic . org>
Indexed By Thread Previous: Re: Pentagon displays due respect for hackers
From: Barry Anderson <bwa @ cednsw . telecom . com . au>
Next: Re: Pentagon displays due respect for hackers
From: Colin Campbell <sgcccdc @ citec . qld . gov . au>

Google
 
Search Internet Search www.greatcircle.com