Re: Are Fragmentation Attacks Still Used for IDS/IPS Evasion?



yep, unfortunately not enough people using host based firewalls and alot of attacks happen inside of where the firewall protects (i.e. local lan)

seclt yuri wrote:
Hi,
I was just reading up on fragmentation attacks using
fragrouter and fragrouter as a mean of IDS/IPS
evasion. However, since almost all firewalls both
commercial and free (iptables for examples) now have
support for fragment reassembly, are fragmentation
attacks still effective? Thanks.


____________________________________________________________________________________
Need a vacation? Get great deals
to amazing places on Yahoo! Travel.
http://travel.yahoo.com/


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • RE: Are Fragmentation Attacks Still Used for IDS/IPS Evasion?
    ... I've seen some firewalls that support inspection of fragmented traffic, ... support IP fragmentation, they certainly messed up when using the TCP ... Are Fragmentation Attacks Still Used for IDS/IPS Evasion? ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: Are Fragmentation Attacks Still Used for IDS/IPS Evasion?
    ... I've seen some firewalls that support inspection of fragmented traffic, ... support IP fragmentation, they certainly messed up when using the TCP ... Are Fragmentation Attacks Still Used for IDS/IPS Evasion? ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Are Fragmentation Attacks Still Used for IDS/IPS Evasion?
    ... Yes but this effectively means that fragmentation ... attacks would be effective. ... where traffic doesn't pass through a firewall. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Are Fragmentation Attacks Still Used for IDS/IPS Evasion?
    ... fragmentation as cover for stealth attacks, ... (internal servers that are separated from Desktops from a router and not a firewall... ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: Block OS Detection
    ... Some firewalls have SYN, IP TLL and ID randomization features on board. ... Subject: Block OS Detection ... buy it or download a solution FREE today! ...
    (Pen-Test)