Re: Pen test of IP stack



hello,

I would also give scapy (last time I checked it was at
http://www.secdev.org/projects/scapy/) a try.
It is python and you can easily script it to run through all the
different options

ZQ

On 8/30/07, axmail@xxxxxxx <axmail@xxxxxxx> wrote:
Hi,

I want to test a new developed network device against vulnerabilities in the IP stack.

I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. But I realized also that I'm facing also hundreds of possible variations in the IP header.

Are there any tools which can already test the stack for the most common vulnerabilities such as the overlapping fragment attack, teardrop and other? In other words it should bombard the stack with invalid IP packets.

I also facing the same problem with DHCP and IGM.

Any help would be welcome and appreciated.

Regards,
Axel

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------




--
---------------------------------------------------------------------
Κρέων
ἐν τῇδ᾽ ἔφασκε γῇ· τὸ δὲ ζητούμενον
ἁλωτόν, ἐκφεύγειν δὲ τἀμελούμενον.
Οιδίπους Τύρρανος [110]
---------------------------------------------------------------------
Creon
In this our land, so said he, those who seek Shall find; unsought, we
lose it utterly.
Oedipus Rex [110]
---------------------------------------------------------------------


Relevant Pages

  • Re: Pen test of IP stack
    ... I want to test a new developed network device against vulnerabilities in the IP stack. ... I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. ... But I realized also that I'm facing also hundreds of possible variations in the IP header. ...
    (Pen-Test)
  • Pen test of IP stack
    ... I want to test a new developed network device against vulnerabilities in the IP stack. ... I found already tools like nemesis or hping2 which makes me able to generate all kind of thinkable packets. ... But I realized also that I'm facing also hundreds of possible variations in the IP header. ...
    (Pen-Test)
  • CORE-20020409: Multiple vulnerabilities in stack smashing protection technologies
    ... Multiple vulnerabilities in stack smashing protection technologies. ... GNU gdb 19990928 ...
    (Bugtraq)
  • [NEWS] Multiple Vulnerabilities in Stack Smashing Protection Technologies
    ... Stack shielding technologies have been developed to protect programs ... techniques to bypass those stack protection technologies, ... security vulnerabilities by overwriting a critical portion of a running ... GNU gdb 19990928 ...
    (Securiteam)
  • Re: Zombie spamming from my PC, Symantec/Spybot, nothing detects it!
    ... "The instant you are without a firewall, you're vulnerable,". ... We are_not_ talking about vulnerabilities that may be there but are ... If the IP stack is vulnerable then the firewall ... The problem of IP stack attacks have nothing to do with ...
    (comp.security.firewalls)