Eicon Networks S92 Manual do Utilizador Página 193

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 209
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 192
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 193
Attacking–theIPFragmentroute:
ThisattackallowsustobogdownFW1.
CheckPointhasadmittedthatanIPfragmentrelatedvulnerabilityexistsinFW14.0
and4.1.AccordingtoCheckPoint:
“Ithasbeendeterminedthatastreamof largeIPfragmentscancausetheFireWall1
codethatlogsthefragmentationeventtoconsumemostavailablehost systemCPU
cycles.Itshouldbenotedthatnounauthorizedaccess,informationleakage,or
fragmentpassingoccurs..Forsecurityreasons(e.g.,overlayattacks)FireWall1
reassemblesallIPfragmentsofadatagrampriortoinspectionagainstthesecurity
policy.Afterreassembly,thepacketisprocessedbytheFireWall1StatefulInspection
engine,andifallowedbythe securitypolicytoproceed,thepacketisrefragmented
andforwarded.Toidentif yandauditattackssuchasPingofDeath,CheckPoint
addedamechanismtoFireWall1outsideofitsstandard loggingcapability tolog
certaineventsthatoccurduringtheFireWall1virtualreassemblyprocess.This
fragmentationloggingtakesplaceonthegatewayitselfandnotonthemanagement
station(relevantf or distributedmanagementdeployments).”
66
Tobeabletolaunchthisattack,weneedatool capableof manipulatingtheICMP
packetsize.Hping
67
isanidealtoolforthispurpose,althoughitrunsonly onLinux
andUnix.If theattackistobelaunchedfromaWindowsbasedmachine,SMURF
2K/XPisrecommended.
SMURF2K/XP,asdescribedbyitsauthorattheRealCoders,allowsustofreely
configurethefollowingoptions:
“
Packets: Number of packets to send.
Source: This is the address, the packets get labeled to 'come from'. If an
internet address can't resolved, you will see a message. If this address
66
http://www.checkpoint.com/techsupport/alerts/ipfrag_dos.html
67
http://www.hping.org/
Vista de página 192
1 2 ... 188 189 190 191 192 193 194 195 196 197 198 ... 208 209

Comentários a estes Manuais

Sem comentários