I understand. What about writing it into the plugin to dump those extra packets in so that it can be detected for sure? Is it common practice to have SNMP open on routers?
John Omernik, MCP Network Consultant Wipfli Ullrich Bertelson LLP (715) 843-7475 -----Original Message----- From: John Lampe [mailto:[EMAIL PROTECTED] Sent: Friday, July 25, 2003 5:17 PM To: Omernik, John; Renaud Deraison; [EMAIL PROTECTED] Subject: Re: [BULK] - Re: Cisco IPv4 DOS ----- Original Message ----- From: "Omernik, John" <[EMAIL PROTECTED]> To: "John Lampe" <[EMAIL PROTECTED]>; "Renaud Deraison" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Friday, July 25, 2003 12:16 PM Subject: RE: [BULK] - Re: Cisco IPv4 DOS >So the idea is that this plugin will block it, but it may fail to detect >that it blocked it. The plugin will eventually block the router, but it will probably not occur at the same time that you are scanning >Is this a shortcoming in the plugin, or in the >framework for the where the plugin is written? Neither. >Or, is this by design? It's not by design, either. The Cisco bug isn't an immediate, reactive bug. Instead, as packets pile up in the queue, the router *eventually* dies. So, I could send a series of malicious, TTL-expiring packets to a router interface, but the router will not go down until the next X amount of packets pile up in the queue after my packets.... John W. Lampe https://f00dikator.aceryder.com/ --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.502 / Virus Database: 300 - Release Date: 7/18/2003 ____________________________________________________________________ Please look below this disclaimer for attachments. This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. This communication may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering the email to the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing, or copying of this email is strictly prohibited. If you have received this email in error please notify the Information Systems Manager by telephone at (715)845-3111 [EMAIL PROTECTED] http://www.wipfli.com
