Fraggle denial of service attack can remotely consume a network`s bandwidth
| fraggle (815) |
Description:
A variant of the smurf denial of service attack called fraggle has been posted to a number of security mailing lists. The attack consists of sending out hundreds of UDP packets from a spoofed source (the victim) to broadcast addresses. All of these hosts then reply to the victim with ICMP unreach messages, which causes the system being attacked to crash.
Platforms Affected:
- Various vendors, Any application
Remedy:
This attack exploits weaknesses in a third party's network configuration and doesn't rely on any flaws in the victim's system. There are, however, ways to minimize the damage produced by such attacks such as reconfiguring border routers to deny packets identified as part of this attack. Refer to your device's documentation to see if this is possible.
Consequences:
Denial of Service
References:
- CIAC Information Bulletin K-032, DDoS Mediation Action List at http://www.ciac.org/ciac/bulletins/k-032.shtml.
- Craig A. Huegen Web site, The Latest in Denial of Service Attacks: "Smurfing" at http://www.pentics.net/denial-of-service/presentations/19971027_smurf_files/frame.htm.
- SANS Institute Resources Web site, Help Defeat Denial of Service Attacks: Step-by-Step at http://www.sans.org/dosstep/index.htm.
- CVE-1999-0514: UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.
Reported:
Mar 15, 1998
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
