Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Killer Pings: sanity check
From: Frank Willoughby <frankw @ in . net>
Date: Fri, 15 Nov 96 07:23:52 -0500
To: uhaas @ tsg-usa . com
Cc: firewalls @ GreatCircle . com

At 12:14 AM 11/15/96 -0500, uhaas @
 tsg-usa .
 com allegedly wrote:

>Hi,
>
>Just performing a sanity check. The "Killer Ping", "Ping o' Death" whatever
>is only a concern from hosts on the SAME network, right? Once the packet
>goes through a router it gets fragmented and re-assembled, right? Does re-
>assembly still cause the machine to crash?

Yes.  BTW, the packet fragmentation is also what keeps the system sending 
the packets from being taken out by its own attack.  When the packets are
re-assembled at the destination system, the resulting packet size exceeds
64K and overflows the buffer - bringing the target system to its knees.


>
>------------------------------------------------------------
>Urban A. Haas
>Open Systems and Network Consulting
>Total Solutions Group
>Phone: (800) 423-8741 Ext. 133; Fax: (612) 831-0509
>Internet: uhaas @
 tsg-usa .
 com -or- mailto:uhaas @
 tsg-usa .
 com
>------------------------------------------------------------


Best Regards,


Frank
Any sufficiently advanced bug is indistinguishable from a feature.
	-- Rich Kulawiec

<standard disclaimer>
The opinions expressed above are of the author and may not 
necessarily be representative of Fortified Networks Inc.

Fortified Networks Inc. - Vendor-Neutral Information Security Consulting 
http://www.fortified.com     Phone: (317) 573-0800     FAX: (317) 573-0817     
Home of the Free Internet Firewall Evaluation Checklist





Follow-Ups:
Indexed By Date Previous: latest linux in the nets.. ?
From: "*-=<saliman @ sunsite . upm . edu . my>=-*" <saliman @ sunsite . upm . edu . my>
Next: Re: Microwave & Satelite
From: Frank Willoughby <frankw @ in . net>
Indexed By Thread Previous: Re: Killer Pings: sanity check
From: peter . maersk-moller @ jrc . it (Peter Maersk-Moller)
Next: Re: Killer Pings: sanity check
From: Can Baysal <baysalc @ boun . edu . tr>

Google
 
Search Internet Search www.greatcircle.com