|
Firewalls (February 1996) |
> > ... ip fragmentation attacks, > > Wozzat? Fragment the IP packet so the address are in different packets, as well as the port number. The router can't buffer them, and can't filter them until it knows all the information. So, it lets them through. And since most firewalls only block on the SYN... tada.. open connection. Darrell Fuhriman Teleport System Administration Follow-Ups:
|