Results 1 to 4 of 4

Thread: Incomplete / Corrupt Packets...

  1. #1
    Senior Member tampabay420's Avatar
    Join Date
    Aug 2002
    Posts
    953

    Question Incomplete / Corrupt Packets...

    Can incomplete / corrupt packets be used in a malicous manner?

    Friend of mine is a Kazaa junkie- runs some win-firewall. Keeps getting logs:: "incomplete packet". There are tons of them- Not sure if it's actually affecting the network or not?
    yeah, I\'m gonna need that by friday...

  2. #2
    Shadow Programmer mmelby's Avatar
    Join Date
    Jul 2002
    Location
    Ft. Myers, FL
    Posts
    291
    Yes. Fragmented packets can be an exploit. There is a database of expliots in this thread.

    http://www.antionline.com/showthread...hreadid=235369
    Work... Some days it's just not worth chewing through the restraints...

  3. #3
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356
    Potentially. There were many bugs in the Microsoft implementation of the TCP/IP stack that would cause reboots (think ping of death), blue screens, and crashes due to exceptional conditions (in previous case ICMP packets > 65535 bytes, (this has long since been fixed)).

    Keep in mind that corrupt packets can be caused by malfunctioning network equipment, servers, errors, etc, and are not necessarily to result of malicious activity. In the case of an 'incomplete packet' I would say reference your firewall manual/documentation for more information, this is a very ambiguous description. If I had to guess i would say that either some packets were very fragmented and you didn't get them all, or that a packet said it was a certain size but it wasn't.

    I would definitely look a little harder at it, maybe use something like ethereal to get a few packet dumps and see if you can't tell exactly what is causing the error to be reported (or you could sanitize the output (remove usernames/passwords/ips), and post it here, I am sure someone would be able to help you (if for some reason I was clueless).

    /nebulus
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

  4. #4
    Senior Member tampabay420's Avatar
    Join Date
    Aug 2002
    Posts
    953

    Unhappy

    I still don't understand the AntiPoints Sys?

    Thanx for the help- I'll have to look further into this...
    yeah, I\'m gonna need that by friday...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •