Security Incidents mailing list archives

Re: Large ICMP Packet, DoS or smth else?


From: Valdis Kletnieks <Valdis.Kletnieks () VT EDU>
Date: Mon, 11 Sep 2000 09:51:19 -0400

On Sun, 10 Sep 2000 15:40:05 EDT, The Picard <thepicard () HOME COM>  said:
also logged a benign browsing session during the same time and from the same
IP. The client OS was a Macintosh running Netscape 4.61 which makes me think
the intent is not really malicious. Is anyone familiar with any tool running
on Mac that's somehow supposed to "optimize the browsing experience"? Last
year I stumbled over a similar tool runing on Windows that sent large and
randomly looking ping packets designed to do MTU discovery and to measure
the speed of the connection

Actually, a number of operating systems do the 'ping for Path MTU discovery'
trick (most notably AIX 4.3 - it was supported in 4.3.0, but 4.3.3 made
it the DEFAULT) for both TCP and UDP connections.

Path MTU discover isn't to measure the "speed" of the connection, it's
to discover the largest packet that can be sent without fragmenting.
See RFC 1191 for the gory details.

--
                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech

Attachment: _bin
Description:


Current thread: