RE: A tool for crafting ESP packets

From: Jose Nazario (jose@biocserver.BIOC.cwru.edu)
Date: 11/29/01


Date: Wed, 28 Nov 2001 22:47:23 -0500 (EST)
From: Jose Nazario <jose@biocserver.BIOC.cwru.edu>
To: amok <amok@orbitallabs.org>
Subject: RE: A tool for crafting ESP packets
Message-ID: <Pine.LNX.4.30.0111282246380.18391-100000@biocserver.BIOC.CWRU.Edu>

On Tue, 27 Nov 2001, amok wrote:

> Very rudimentary example:
>
> <IP Header>
> <ESP Start>
> Security Parameters Index (SPI) (32 bit)
> Sequence Number (32 bit)
> Encrypted Payload (Variable length)
> <ESP End>

you forgot the trailer for ESP. though forgetting it and seeing if you can
disrupt/DoS a VPN with broken ESP frames would be interesting.

____________________________
jose nazario jose@cwru.edu
                           PGP: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • R: Pen-Testing help (Compaq Insight & htsearch)
    ... This web server happens to be in front of their ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Application & Iplanet/Apache web server vulnerability and penetration testing
    ... I don't know what to do on the web servers other than delete example ... Any suggestions on iPlanet and Apache security? ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)