Pen test of IP stack



Hi,

I want to test a new developed network device against vulnerabilities in the IP stack.

I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. But I realized also that I'm facing also hundreds of possible variations in the IP header.

Are there any tools which can already test the stack for the most common vulnerabilities such as the overlapping fragment attack, teardrop and other? In other words it should bombard the stack with invalid IP packets.

I also facing the same problem with DHCP and IGM.

Any help would be welcome and appreciated.

Regards,
Axel

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • CORE-20020409: Multiple vulnerabilities in stack smashing protection technologies
    ... Multiple vulnerabilities in stack smashing protection technologies. ... GNU gdb 19990928 ...
    (Bugtraq)
  • Re: Pen test of IP stack
    ... I want to test a new developed network device against vulnerabilities in the IP stack. ... I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. ... But I realized also that I'm facing also hundreds of possible variations in the IP header. ...
    (Pen-Test)
  • [NEWS] Multiple Vulnerabilities in Stack Smashing Protection Technologies
    ... Stack shielding technologies have been developed to protect programs ... techniques to bypass those stack protection technologies, ... security vulnerabilities by overwriting a critical portion of a running ... GNU gdb 19990928 ...
    (Securiteam)
  • Re: Pen test of IP stack
    ... I want to test a new developed network device against vulnerabilities in the IP stack. ... I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. ... But I realized also that I'm facing also hundreds of possible variations in the IP header. ...
    (Pen-Test)
  • Re: Zombie spamming from my PC, Symantec/Spybot, nothing detects it!
    ... "The instant you are without a firewall, you're vulnerable,". ... We are_not_ talking about vulnerabilities that may be there but are ... If the IP stack is vulnerable then the firewall ... The problem of IP stack attacks have nothing to do with ...
    (comp.security.firewalls)