"Paul D. Robertson" wrote:
> 
> On Sat, 13 Apr 2002, Mikael Olsson wrote:
> 
> > CPU load logarithmically. The effects of a low-bandwidth jolt2 were
> > really interesting to watch.)
> 
> You should see what happens when someone fixes the code.  We've got
> someone who looked at Jolt2 and said "Oh, I can see what they MEANT to do
> here..."

Interesting. This wouldn't be the PoC code that phonix posted
to bugtraq, would it? Because I toyed around with that quite
extensively, added offset randomization/control, IP packet ID 
randomization/control,  MF/DF control, rate control, etc etc 
and couldn't get it to behave differently.

And in _that_ particular code snippet, I didn't see any evidence
of "whoops, that's not what I inteded" except for some ugliness
that makes it easier to write IDS signatures ;)

The jolt2.c I'm talking about (and instrumented version) is at:
http://c0ffee.badf00d.org/src/jolt2-phonix.c
http://c0ffee.badf00d.org/src/jolt2-phonix-instrumented.c

The instruemted version _did_ however prove that all you need is about
a ~100kbps stream, and the offset you use doesn't change anything, as 
long as it's nonfirst fragments.



-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 �RNSK�LDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com

Ynlre 8 frphevgl fbyhgvbaf: uggc://yneg.onqs00q.bet
_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls

Reply via email to