Renaud wrote:
> Here is the plugin. The real issue is not to block the remote router,
> but rather properly detect that its keys are full. The current method
> may not work well (ie: the plugin will block the router but may fail
> to detect it has actually been loggued). Returns of experience are
> welcome.

There is only a small statistical chance that the plugin will report on
truly vulnerable systems.  While the attack is valid, the DoS doesn't occur
until the queue is full.  So, scanning your systems may give you a false
sense of security until 12 hours later when all your routers dissapear from
the network....

In this instance, the SNMP check is the better...

John W. Lampe
https://f00dikator.aceryder.com/





---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.502 / Virus Database: 300 - Release Date: 7/18/2003

Reply via email to