Home page logo

bugtraq logo Bugtraq mailing list archives

Re: IGMP denial of service vulnerability
From: Marty Schoch <mschoch () multicasttech com>
Date: 14 Jun 2002 14:45:33 -0400

All IGMP packets that are not multicast ethernet addresses should be 

Depending on the implementation of router R in linked document, couldn't
there still be a problem in the following scenario.

Host H1 is a member of two groups and
Host H2 sends a membership report for group to group

Host H1 will obviously see this report as well.
Looking briefly at the code it appears host H1 may still consider this
an acceptable report from another host.  If, and I haven't tested any
router configurations, router R does not consider this a valid report
for the group then the same DOS effect may occur.

The RFC says that membership reports should be sent to the group for
which the report applies.  Why not tighten the code down all the way, to
check not just that the report is multicast, but that all the addresses

Marty Schoch
<mschoch () multicasttech com>

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]