Denial of Service A/acks
Cunsheng Ding Department of CSE HKUST, Hong Kong
Acknowledgements: Materials are taken from the Internet
COMP4631 1
Denial of Service A/acks Cunsheng Ding Department of CSE HKUST, - - PowerPoint PPT Presentation
Denial of Service A/acks Cunsheng Ding Department of CSE HKUST, Hong Kong Acknowledgements: Materials are taken from the Internet COMP4631 1 Agenda of this lecture Zombie computers, bots, botnets Denial of service (DoS) a/acks
COMP4631 1
COMP4631 2
COMP4631 3
COMP4631 4
COMP4631 5
COMP4631 6
COMP4631 7
COMP4631 8
COMP4631 9
COMP4631 10
COMP4631 11
COMP4631 12
COMP4631 13
COMP4631 14
COMP4631 15
COMP4631 16
COMP4631 17
COMP4631 18
COMP4631 19
COMP4631 20
COMP4631 21
COMP4631 22
COMP4631 23
Service denied to legiPmate users
COMP4631 24
COMP4631 25
Ping of Death Source: learn-networking.com
COMP4631 26
COMP4631 27
COMP4631 28
– h/p://gregsumner.blogspot.hk/2013/02/how-to-spoof-your-ip-address-using-nmap.html – h/p://seclists.org/nmap-hackers/2004/0008.html
COMP4631 29
COMP4631 30
Address, Port number, Seq x Recorded in a table of known TCP connecPons Server in LISTEN State Vulnerability: Unboundedness
COMP4631 31
COMP4631 32
COMP4631 33
COMP4631 34
– Send source-forged ICMP echo packet requests from remote loca<ons – Packets directed to IP broadcast addresses
– When enPre network responds, successful smurf DoS has been performed on the target network
– Smurf DoS a/ack with single/mulPple intermediary(s) – Analyze network routers that do not filter broadcast traffic – Look for networks where mulPple hosts respond
COMP4631 35
COMP4631 36
– The bug causes the TCP/IP fragmentaPon re-assembly code to improperly handle overlapping IP fragments – A 4000 bytes of data is sent as
COMP4631 37
COMP4631 38
COMP4631 39
COMP4631 40
COMP4631 41
COMP4631 42
COMP4631 43
COMP4631 44
COMP4631 45