-
October 16th, 2002, 07:58 PM
#1
Incomplete / Corrupt Packets...
Can incomplete / corrupt packets be used in a malicous manner?
Friend of mine is a Kazaa junkie- runs some win-firewall. Keeps getting logs:: "incomplete packet". There are tons of them- Not sure if it's actually affecting the network or not?
yeah, I\'m gonna need that by friday...
-
October 16th, 2002, 08:04 PM
#2
Yes. Fragmented packets can be an exploit. There is a database of expliots in this thread.
http://www.antionline.com/showthread...hreadid=235369
Work... Some days it's just not worth chewing through the restraints...
-
October 16th, 2002, 08:04 PM
#3
Potentially. There were many bugs in the Microsoft implementation of the TCP/IP stack that would cause reboots (think ping of death), blue screens, and crashes due to exceptional conditions (in previous case ICMP packets > 65535 bytes, (this has long since been fixed)).
Keep in mind that corrupt packets can be caused by malfunctioning network equipment, servers, errors, etc, and are not necessarily to result of malicious activity. In the case of an 'incomplete packet' I would say reference your firewall manual/documentation for more information, this is a very ambiguous description. If I had to guess i would say that either some packets were very fragmented and you didn't get them all, or that a packet said it was a certain size but it wasn't.
I would definitely look a little harder at it, maybe use something like ethereal to get a few packet dumps and see if you can't tell exactly what is causing the error to be reported (or you could sanitize the output (remove usernames/passwords/ips), and post it here, I am sure someone would be able to help you (if for some reason I was clueless).
/nebulus
There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.
(Merovingian - Matrix Reloaded)
-
October 16th, 2002, 08:12 PM
#4
I still don't understand the AntiPoints Sys?
Thanx for the help- I'll have to look further into this...
yeah, I\'m gonna need that by friday...
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|