A rogue's gallery of DoS attacks

Breaking TCP/IP implementations

The canonical example of an attack that goes after TCP/IP implementation weaknesses is the Ping of Death attack. In this exploit, your enemy creates an IP packet that exceeds the IP standard's maximum 65,536-byte size. When this bloated packet arrives it crashes systems that are using a vulnerable TCP/IP stack and operating system.

All modern operating systems and stacks are immune to the Ping of Death attack, but older Unix systems may still be vulnerable.

Another attack that relies on poor TCP/IP implementation is Teardrop, which exploits defects in the way systems reassemble IP packet fragments. On their way from hither to yon on the Internet, an IP packet may be broken up into smaller pieces. Each of these still has the original IP packet's header, as well as an offset field that identifies which bytes of the original packet it contains. With this information, an ordinary broken packet is reassembled at its destination and network continues uninterrupted.

When a Teardrop attack hits, your server is bombarded with IP fragments that have overlapping offset fields. If your server or router can't disregard these fragments and attempts to reassemble them, your box will go castors up quickly. If your systems are up-to-date, or if you have a firewall that blocks Teardrop packets, you shouldn't have any trouble.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Stilgherrian The challenge of government 2.0
    The Government 2.0 Taskforce released its draft report last week, and its recommendations for Open Government almost reads like a manifesto. Stilgherrian's guest on Patch Monday this week is the chair of the Taskforce, Nicholas Gruen.
  • Array The people's NBN, now with 1001 uses
    Faced with a renewed threat in newly-appointed Tony Abbott and unknown-quantity communications portfolio ankle-biter Tony Smith, Stephen Conroy responded this week in the way any politician would: he gave lots, and lots, and lots of speeches.
  • Array A guide to the future of the internet
    Last week we looked at the history of the internet in Australia. It's been around for 20 years and changed our lives in so many ways. Imagine what it could do given another 20 years.
  • More blogs »

Tags

Back to top

Featured