Re: A tool for crafting ESP packets

From: Loki (loki@fatelabs.com)
Date: 11/24/01


Message-Id: <200111242146.fAOLkG724319@pa-lnx01.fatelabs.com>
From: Loki <loki@fatelabs.com>
To: "Nelson Brito" <nelson@tw-award.com>, <pen-test@securityfocus.com>
Subject: Re: A tool for crafting ESP packets
Date: Sat, 24 Nov 2001 16:46:16 -0500

Nelson,

Can you give me a URL to where it says NMAP crafts ESP packets, as I've read
all through the documentation and man page. Also, AH isn't a "packet" it
provides authentication mechanisms for IP datagrams and protection against
replay attacks.

RFC 2402:
ftp://ftp.isi.edu/in-notes/rfc2402.txt

Loki
www.fatelabs.com

 

On Saturday 24 November 2001 04:44 pm, Nelson Brito wrote:
> I guess that the nmap BETA versions can send ESP, AH and a lot of anothers
> protocol's packet.
>
> If you wanna do something differente, just like customize the packets, use
> the power, read the code, LUKE.
>
> Sem mais,

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: A tool for crafting ESP packets
    ... A tool for crafting ESP packets ... I wonder what kind of "customized" IPSEC packets you ... > Fate Research Labs has started immediate development of an auditing tool for ... > This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: A tool for crafting ESP packets
    ... A tool for crafting ESP packets ... If this is in fact not the case and nmap does generate fully compliant IPSec ... >>Can you give me a URL to where it says NMAP crafts ESP packets, ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ESP and AH protocols and NAT.
    ... :Imagine I would use one IP only for this kind of traffic (IPsec). ... :I know IPsec travels through udp. ... There is no point in NAT'ing AH packets. ... if you are using nat-traversal then because the ESP packets will ...
    (comp.dcom.sys.cisco)
  • Re: How can I stop ESP protocol DOS/annoyance packets?
    ... > 65.114.197.34 is keeping the modem connected with these ESP packets, ... QWest, or that it is an attack and the IP number that my iptables firewall ...
    (comp.security.firewalls)
  • Re: How can I stop ESP protocol DOS/annoyance packets?
    ... > 65.114.197.34 is keeping the modem connected with these ESP packets, ... QWest, or that it is an attack and the IP number that my iptables firewall ...
    (comp.os.linux.security)