So the idea is that this plugin will block it, but it may fail to detect that it blocked it. Is this a shortcoming in the plugin, or in the framework for the where the plugin is written? Or, is this by design? Thanks for your quick replys! John
-----Original Message----- From: John Lampe [mailto:[EMAIL PROTECTED] Sent: Friday, July 25, 2003 5:02 PM To: Renaud Deraison; [EMAIL PROTECTED] Subject: [BULK] - Re: Cisco IPv4 DOS Renaud wrote: > Here is the plugin. The real issue is not to block the remote router, > but rather properly detect that its keys are full. The current method > may not work well (ie: the plugin will block the router but may fail > to detect it has actually been loggued). Returns of experience are > welcome. There is only a small statistical chance that the plugin will report on truly vulnerable systems. While the attack is valid, the DoS doesn't occur until the queue is full. So, scanning your systems may give you a false sense of security until 12 hours later when all your routers dissapear from the network.... In this instance, the SNMP check is the better... John W. Lampe https://f00dikator.aceryder.com/ --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.502 / Virus Database: 300 - Release Date: 7/18/2003 ____________________________________________________________________ Please look below this disclaimer for attachments. This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. This communication may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering the email to the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing, or copying of this email is strictly prohibited. If you have received this email in error please notify the Information Systems Manager by telephone at (715)845-3111 [EMAIL PROTECTED] http://www.wipfli.com
