OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Przemyslaw Frasunek (venglinfreebsd.lublin.pl)
Date: Fri Dec 14 2001 - 05:08:59 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hello,

    Zyxel Prestige 681 SDSL router is vulnerable to *remote* denial of service.
    By sending malformed packets, it is possible to bring down DSL link for few
    minutes. The problem persists only if packets come from DSL interface, not
    from Ethernet. ZyNOS reports that line is synchronizing and it takes about
    2-3 minutes before link is up.

    The workaround is to switch off routing and put device in bridging mode.
    Zyxel support has been notified, I won't release details of attack, until
    ZyNOS will be patched.

    -- 
    * Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
    * Inet: przemyslawfrasunek.com ** PGP: D48684904685DF43EA93AFA13BE170BF *