On Fri, Jul 25, 2003 at 03:02:01PM -0700, John Lampe wrote:
> There is only a small statistical chance that the plugin will report
> on truly vulnerable systems. While the attack is valid, the DoS
> doesn't occur until the queue is full.
But it seems that this script sends out 46*#proto = 4*46 packets which
should fill up the queue since it is only 56 packets long. (though
I haven't tested this script yet)
I have positively tested this vulnerability with hping2 on local
subnet with TTL 0 and 1. There is a rumor about problems with not
being able to exploit it remotely (more than one hop away, with
corresponding TTL) but I wasn't able to move my testing device
somewhere out yet to re-check... any clues/experiences?
--
Martin Mačok http://underground.cz/
[EMAIL PROTECTED] http://Xtrmntr.org/ORBman/