From owner-freebsd-questions Mon Dec 9 05:28:45 1996 Return-Path: Received: (from root@localhost) by freefall.freebsd.org (8.8.4/8.8.4) id FAA03025 for questions-outgoing; Mon, 9 Dec 1996 05:28:45 -0800 (PST) Received: from tsi.gte.com ([205.174.176.40]) by freefall.freebsd.org (8.8.4/8.8.4) with SMTP id FAA03020 for ; Mon, 9 Dec 1996 05:28:43 -0800 (PST) Received: from g07.tsi.gte.com ([205.174.179.141]) by tsi.gte.com (5.x/SMI-SVR4) id AA02888; Mon, 9 Dec 1996 08:29:36 -0500 Date: Mon, 9 Dec 1996 08:29:36 -0500 Message-Id: <1.5.4.16.19961209082754.491f78d0@uhuru.tsi.gte.com> X-Sender: smorris@uhuru.tsi.gte.com X-Mailer: Windows Eudora Light Version 1.5.4 (16) Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" To: Mike Kercher , freebsd-questions@freebsd.org From: Scott Morris Subject: Re: Is this Ping of Death for real? Sender: owner-questions@freebsd.org X-Loop: FreeBSD.org Precedence: bulk Oh yes, this is a very real problem. The "specially formatted ping" they refer to is a ping with a packet size >65K. ie ping -l 65777. Fortunately my testing has shown FreeBSD to be immune,:) wish I could say the same for my other systems.:( At 09:32 AM 12/7/96 -0600, you wrote: >>X-Authentication-Warning: wb5fnd.tech.uh.edu: majordom set sender to owner-houston-irc using -f >>Date: Thu, 5 Dec 1996 12:59:16 -0600 (CST) >>X-AUTH: NOLNET SENDMAIL AUTH >>X-Sender: skeeter@nol.net >>To: houston-irc@wb5fnd.tech.uh.edu >>From: skeeter@nol.net (Paul ) >>Sender: owner-houston-irc@wb5fnd.tech.uh.edu >>Reply-To: "Houston IRC List" >>X-Status: >> >>Check this out!!!! Sounds like bull***t to me!!! >> >>"PING OF DEATH" SECURITY FLAW >>Software programmers are scrambling to fix a recently documented security >>flaw found in the "ping" Internet function, which is used to check whether a >>piece of hardware is properly hooked up to a network. The problem arises >>when a cracker sends a booby-trapped ping command, nicknamed the "ping of >>death," to a targeted computer. The computer responds by rebooting, >>crashing or shutting down. Computer security expert Eugene Spafford says >>he's seen two such attacks on his campus, neither of which was malicious: >>"You just track down where this came from and have a long talk with them, >>with or without a blunt instrument." For more information on the "ping of >>death," check out < http://www.sophist.demon.co.uk/ping/ >. (Chronicle of >>Higher Education 22 Nov 96 A23) >> >> >> >~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~ >Syn-Work Media, Inc. | WWW Development & Hosting | Life Safety >http://www.synwork.com | Systems Integration | CCTV >mike@synwork.com | Voice/Data/Fiber | Access Control >Flaq on IRC | Dukane Distributor | BICSI/RCDD >:|:|:|: Powered By FreeBSD :|:|:|: >Turning PC's Into Workstations >~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~'`^`'~*-,._.,-*~ > ____________ Scott Morris GTE Telecommunication Services smorris@tsi.gte.com 813-273-3917 *** My opinions do not necessarily reflect those of my employer. ***