OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Naptha - New DoS
From: Dug Song (dugsongMONKEY.ORG)
Date: Sun Dec 10 2000 - 15:57:21 CST


On Sun, Dec 10, 2000 at 09:14:23AM -0600, Simple Nomad wrote:

> Regarding scut's comment that 3wahas already does this -- the answer
> to that is not exactly. Forging just the TCP packets will work to a
> certain extent, forging the generated arp requests as well will
> cause much more effective and quicker resource depletion.

um, i released a simplified version of my "nakji" tool to do just that
back in April, when Stanislav Shalunov published his "netkill" attack.
state-holding attacks against TCP weren't really news then, and they
certainly aren't news now.

        http://www.deja.com/getdoc.xp?AN=616571925

Stanislav did, however, identify some novel ways to maximize the
impact of such an attack by exploiting exceptionally bad failure
modes, including forcing the remote TCP into an indefinite persist
state with pending data for retransmission on a closed window.

i doubt that "NAPTHA" pulls any new tricks, but i've never seen it.

-d.

---
http://www.monkey.org/~dugsong/