IP fragmentation

From: Kuk-hyeon Lee (errai@hitel.net)
Date: 12/04/01


From: "Kuk-hyeon Lee" <errai@hitel.net>
To: <focus-sun@security-focus.com>
Date: Tue, 4 Dec 2001 10:28:25 +0900

Hi all. I making IDS evasion tool in Solaris. and I want to fragment ip
header
with LIBNET in Solaris 8. But I succeed it in Linux system, failed in
Solaris System.
I used IP_MF frag, but all packets have [DF] frag.

ex1) nomal packet (in Linux)
12.102.204.28 > 10.3.56.2: (frag 666:1480@60680+)
12.102.204.28 > 10.3.56.2: (frag 666:1480@62160+)

ex2) wrong packet(in Solaris)
22:19:06.566965 12.102.204.28 > 10.3.56.2: icmp: echo request (DF)
22:19:06.567009 12.102.204.28 > 10.3.56.2: icmp: echo request (DF)
(Don't fragmentation)

ex1 and ex2 is same source. Solaris kernel working something to obstruct
fragmentation packet? or Libnet's problem?

Thanks in advance.

--
Lee, Kuk-hyeon



Relevant Pages

  • Re: Is anything else then Solaris used on UltraSparc Machines.
    ... > familiar with Solaris. ... The same thing cannot be said for Linux. ... Solaris x86 seems better with more expensive hardware whereas Linux ... it for Solaris (SPARC). ...
    (comp.unix.solaris)
  • Re: Is anything else then Solaris used on UltraSparc Machines.
    ... They are just not there right now, just like Linux isn't there ... scalability, real-time support, standards compliance, volume ... > Sure there is a lot of pre-packaged software of Solaris, ... but it is often more hassle on Solaris (even SPARC). ...
    (comp.unix.solaris)
  • Re: Is anything else then Solaris used on UltraSparc Machines.
    ... > I think there are good reasons for using Linux in place of Solaris ... The same thing cannot be said for Linux. ... Solaris x86 seems better with more expensive hardware whereas Linux ... it for Solaris (SPARC). ...
    (comp.unix.solaris)
  • Re: Linux Advocates Fear Solaris 10.
    ... >> will want, and will get, with Linux and repositories of GPL software. ... Solaris has 95% of Linux ... Okay, so take OUT the Linux compatibility layer, and any of the GPL ... SUN, however, can 'open source' their Solaris, package a shitload of GPL ...
    (comp.unix.solaris)
  • Re: Why is SUN falling so far behind IBM?
    ... > x86 delivery to be later than Linux. ... > communicated from day one that JDS was a solution that ran on ... substantial lead over Solaris in the x86 world. ... > great success with the Sun Rays and Sun Blades running the JDS stack. ...
    (comp.unix.solaris)