Security Basics mailing list archives
Re: Smurf ,land attacks
From: Donnie Tognazzini <don_tog () yahoo com>
Date: Sat, 16 Nov 2002 23:03:53 -0800 (PST)
If you want full control of network read/writes use libnet/libpcap.. have a look at tcpdump.org.. Using libnet/libpcap you can write directly to the wire. --- Paulo Abrantes <ghostrider () box sk> wrote:
Hello Vik, What the attacker does is not allowing the Kernel to fill in the IP datagram from the packet he's spoofing, and filling it by himself/herself. How can (s)he do that? Well, the best way I know, and probably is the way that land.c (that you mention) uses (I do do not know the source of that program) is creating a RAW socket. Then using a function called setsocketop() enabling the option IP_HDRINCL which allows you to include your own IP Header. This way it's you that create the all the IPheader including IP Source Address. For further information give a look at raw(7) man page. Regards, P. Abrantes On Sat, 9 Nov 2002 13:10:11 -0700 "Vik Evans" <vevans () packeteye phxcoxmail com> wrote:My question is this: how does an attackeraccomplish modifying a packet andsending it; such as in a land.c attack - how doeshe modify the packet toreflect the victim's source and destination IP andthen send it onto thewire? -----Original Message----- From: Fuchs Bernhard[mailto:Bernhard.Fuchs () itellium com]Sent: Tuesday, November 05, 2002 5:58 AM To: 'vijay vikram shreenivos';security-basics () securityfocus comSubject: AW: Smurf ,land attacks Hi there! with "IP spoofing" you give a different sourceaddress to the packet. theaddress is different to your real address. You dothis for cloaking yourscan or if company A scans company B and spoofesthe address of company c.so company b thinks it is company c scanning them!o.k.? but company a willnot get any results back! this is mostly to cloakyour own scan.Smurf is a DoS-Attack (denial of service) You Amplifi your ping through a big network. Youping a subnet likex.x.x.255 with an SPOOFED IP-Adress and everycomputer on that big netresponses to the poor little machine that has theIP-Adress. Think of classB subnet with a few hosts reply to a ADSLconnected machine... 1500kbdownload and 196 kb upload :-) land attack is a TCP SYN packet that has the ipaddress and port number forthe source set to the same as the ip address andport number for thedestination. the server connects to itself. any comments? by the way, google knows it too :-) Mit freundlichen Grüßen/ sincerely yours Bernhard Fuchs Junior System-Engineer IT-Infrastruktur ITELLIUM Systems & Services GmbH Fürther Straße 205 90429 Nürnberg Tel.: +49-911-14-27321 Fax: +49-911-14-22016 mailto:bernhard.fuchs () itellium com http://www.itellium.com This email is confidential. If you are not theintended recipient, you mustnot disclose or use the information contained init. If you have receivedthis mail in error, please tell us immediately byreturn email and deletethe document. E-mails to and from the company aremonitored for operationalreasons and in accordance with lawful businesspractices. The contents ofthis email are those of the individual and do notnecessarily represent theviews of the company. The company accepts noresponsibility once an e-mailand any attachments is sent. -----Ursprüngliche Nachricht----- Von: vijay vikram shreenivos[mailto:karpagamekapali () rediffmail com]Gesendet: Samstag, 2. November 2002 08:15 An: security-basics () securityfocus com Betreff: Smurf ,land attacks Hi list, Can someone give the EXACT differences btw SMURF LAND and IP soofing attacks. karpagamekapalidurgau
__________________________________________________________
Give your Company an email address like ravi @ ravi-exports.com. Sign up for RediffmailPro today!Know more. http://www.rediffmailpro.com/signup/
__________________________________________________ Do you Yahoo!? Yahoo! Web Hosting - Let the expert host your site http://webhosting.yahoo.com
Current thread:
- AW: Smurf ,land attacks Fuchs Bernhard (Nov 09)
- RE: Smurf ,land attacks Vik Evans (Nov 11)
- Re: Smurf ,land attacks Paulo Abrantes (Nov 12)
- Re: Smurf ,land attacks Donnie Tognazzini (Nov 18)
- Re: Smurf ,land attacks phani (Nov 14)
- Re: Smurf ,land attacks Paulo Abrantes (Nov 12)
- RE: Smurf ,land attacks Vik Evans (Nov 11)