Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Killer Pings
From: JOHNSON @ neu . edu
Date: Fri, 15 Nov 1996 06:57:50 -0500 (EST)
To: firewalls @ GreatCircle . com

>Hi Urban !

>> Just performing a sanity check. The "Killer Ping", "Ping o' Death" whatever
>> is only a concern from hosts on the SAME network, right? Once the packet
>> goes through a router it gets fragmented and re-assembled, right? Does re-
>> assembly still cause the machine to crash?

>Yes, it will crash. It is not the individual packet which is the problem.
>It is all packets which together form a deadly ICMP. However its not
>only the ICMP which gives you this problem, but probably most protocols.

>The only fix possible is to get it right at the kernel level for
>the TCP/IP.

>No simple device (like a gateway) can remove the problem by doing sanity
>check. To do that it would have to keep track of all packets in all
>connections. This is not feasable without using a lot of both RAM
>and processing power. Worst of all, it will introduce unacceptable latency.

>Regards

>Peter Maersk-Moller

     When I received the patch for my ALPHA systems it changed a module 
which belongs to the packet defragmenter/reassembler.  This indicate 
that the problem was higher up than anything a router or firewall can 
block.  It might crash the firewall.  It might crash anything that had 
to use the complete packet.  Just moving packet fragments around 
wouldn't cause a problem as far as I can tell.  Given length limits on 
various media there's a limit to how big a fragment can be.

     Experiments here seem to show this anyway.  Please keep in mind 
that I could be completely wrong.  It's been known to happen.

Chris J.
NU

============================================================================
Chris Johnson                            Internet: johnson @
 nuhub .
 dac .
 neu .
 edu
Assistant Director, Systems              BITNET:   johnson @
 nuhub
Division of Academic Computing           Voice:    617.373.3300
Northeastern University, 39RI            FAX:      617.373.8600
360 Huntington Ave.                      Half of all doctors graduated 
Boston, MA. U.S.A. 02115                 in the lower 50% of the class
============================================================================

Indexed By Date Previous: Question ?
From: RAGHAVENDRA M <cs93318 @ rohini>
Next: latest linux in the nets.. ?
From: "*-=<saliman @ sunsite . upm . edu . my>=-*" <saliman @ sunsite . upm . edu . my>
Indexed By Thread Previous: Re: Question ?
From: peter @ baileynm . com (Peter da Silva)
Next: latest linux in the nets.. ?
From: "*-=<saliman @ sunsite . upm . edu . my>=-*" <saliman @ sunsite . upm . edu . my>

Google
 
Search Internet Search www.greatcircle.com