Snort mailing list archives

RE: RV: Snort exploits


From: counter.spy () gmx de
Date: Wed, 17 Apr 2002 21:15:16 +0200 (MEST)

Gotcha!
This is what I wanted to know (and it spares a dedicated machine;):

<snippet of fragroute(8)>
"Unlike fragrouter (8), this program only affects packets originating from
the local machine
destined for a remote host. Do not enable IP forwarding on the local
machine."
</snippet of fragroute(8)>

I don't know yet what else has been changed in comparison to fragrouter.
We'll see...

Ronneil, I am afraid I can't get into testing fragroute right now, because I
have to get going with writing my thesis and doing tests with taps and
stuff.
The program will have to wait, but most likely your problems will be solved
by then.
Please drop me a mail, when you know how to use it, I would be very
interested in your results.

Greetings,
Detmar

Hi,

I actually want to test fragroute also. it's installed on my system but I
just
don't know how to use it to test against my vulnerable wu-ftpd that also
sites
on the network as with my snort. Any idea on how I would test it?

It's because, I only know how to run fragroute as 

mytestmachine# fragroute 172.16.0.107
fragroute: tcp_seg -> ip_frag -> ip_chaff -> order -> print

That's it. I don't know how to inject the exploit to my wuftpd.

Thanks.




-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: