----- Original Message -----
From: "Omernik, John" <[EMAIL PROTECTED]>
To: "John Lampe" <[EMAIL PROTECTED]>; "Renaud Deraison"
<[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>
Sent: Friday, July 25, 2003 12:16 PM
Subject: RE: [BULK] - Re: Cisco IPv4 DOS


>So the idea is that this plugin will block it, but it may fail to detect
>that it blocked it.

The plugin will eventually block the router, but it will probably not occur
at the same time that you are scanning

>Is this a shortcoming in the plugin, or in the
>framework for the where the plugin is written?

Neither.

>Or, is this by design?

It's not by design, either.  The Cisco bug isn't an immediate, reactive bug.
Instead, as packets pile up in the queue, the router *eventually* dies.  So,
I could send a series of malicious, TTL-expiring packets to a router
interface, but the router will not go down until the next X amount of
packets pile up in the queue after my packets....

John W. Lampe
https://f00dikator.aceryder.com/



---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.502 / Virus Database: 300 - Release Date: 7/18/2003

Reply via email to