OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Networking theories
From: Blue Boar (BlueBoarTHIEVCO.COM)
Date: Sun May 07 2000 - 23:27:35 CDT


> Just as a thought, if such a DoS was so difficult, why would I be
> logging lots of ICMP Type 3 packets at my firewall from IP's that have
> not been connected to? The most recent one (involving approx 200
> packets over a few seconds) was supposedly from 10.240.x.x, not even
> available on my internal network. Quite obviously these packets are
> spoofed, but if their is no real way to D0S a system with them, why
> would someone spoof them?
> Unfortunately, using Windows 9x, I am unable to give you tcp dumps of
> the packets....if anyone knows of a program to do this, please let me
> know.
>

Any router between two nodes may generate ICMP unreachable messages.
Kinda broken IMNSHO.. firewalls have no idea what IP to expect
such messages from under those circumstances.

                                        BB