On Fri, Jul 25, 2003 at 03:02:01PM -0700, John Lampe wrote:

> There is only a small statistical chance that the plugin will report
> on truly vulnerable systems.  While the attack is valid, the DoS
> doesn't occur until the queue is full.

But it seems that this script sends out 46*#proto = 4*46 packets which
should fill up the queue since it is only 56 packets long. (though
I haven't tested this script yet)

I have positively tested this vulnerability with hping2 on local
subnet with TTL 0 and 1. There is a rumor about problems with not
being able to exploit it remotely (more than one hop away, with
corresponding TTL) but I wasn't able to move my testing device
somewhere out yet to re-check... any clues/experiences?

-- 
         Martin Mačok                 http://underground.cz/
   [EMAIL PROTECTED]        http://Xtrmntr.org/ORBman/

Reply via email to