RE: Pen test of IP stack




Are there any tools which can already test the stack for the
most common vulnerabilities such as the overlapping fragment
attack, teardrop and other?

Yes, you can look at ISIC, it's a great TCP/IP stack fuzzer
http://www.packetfactory.net/Projects/ISIC/ If you are looking for specific
attacks then you will probably need to use something IMPacket (Python) or
nemesis to create those exact scenarios.

JS



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------