Source code/Pseudo Code:
#!/bin/csh
foo:
ipsend -i -P gre > /dev/null
goto foo:
The above code simply sends malformed GRE packets to the victim
server. Then loops and repeats until the program is aborted.
For detailed log notes, please see Log notes section in the Additional
Information portion of this document (before the Bibliography).
Exploit #3 Details
Name:
PPTP attack #3 using apsend to send malformed packets to GRE
protocol, causing system resources to become consumed and server unusable.
Variants:
Another variation on the “Malformed PPTP Packet Stream”
vulnerability
Operating Systems:
All versions of NT, all service packs.
Protocols/Services:
PPTP GRE protocol 47
Brief Description:
Malformed packets are sent to the service listening for Protocol 47 (GRE) on the
server. This is a bit longer attack than #1. This attack is cumulative. It can be
paused and then continued later, and still eventually accumulates to the same
effect, the system becomes unusable.
0
Do'stlaringiz bilan baham: |