How to protect against it:
Same as Attack #1 description:
Download MS patch from
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bull
etin/MS01-009.asp
or install service Pack 6a or migrate to Windows 2000.
Another possible work around is to try to filter GRE packets by their
source address at your perimeter, only allowing traffic from known addresses.
However, since GRE is a connectionless protocol, source address spoofing is
trivial. There are a number of tools and sites describing how to abuse any
networks that allow any kind of GRE traffic. If an attacker can guess what
source addresses are allowed, the attacker can simply send packets with the
allowed source IP forged and bypass the filtering.
Do'stlaringiz bilan baham: |