Renaud wrote: > Here is the plugin. The real issue is not to block the remote router, > but rather properly detect that its keys are full. The current method > may not work well (ie: the plugin will block the router but may fail > to detect it has actually been loggued). Returns of experience are > welcome.
There is only a small statistical chance that the plugin will report on truly vulnerable systems. While the attack is valid, the DoS doesn't occur until the queue is full. So, scanning your systems may give you a false sense of security until 12 hours later when all your routers dissapear from the network.... In this instance, the SNMP check is the better... John W. Lampe https://f00dikator.aceryder.com/ --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.502 / Virus Database: 300 - Release Date: 7/18/2003
