📄 477.htm
字号:
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<title>CTerm非常精华下载</title>
</head>
<body bgcolor="#FFFFFF">
<table border="0" width="100%" cellspacing="0" cellpadding="0" height="577">
<tr><td width="32%" rowspan="3" height="123"><img src="DDl_back.jpg" width="300" height="129" alt="DDl_back.jpg"></td><td width="30%" background="DDl_back2.jpg" height="35"><p align="center"><a href="http://apue.dhs.org"><font face="黑体"><big><big>apue</big></big></font></a></td></tr>
<tr>
<td width="68%" background="DDl_back2.jpg" height="44"><big><big><font face="黑体"><p align="center"> ● UNIX网络编程 (BM: clown) </font></big></big></td></tr>
<tr>
<td width="68%" height="44" bgcolor="#000000"><font face="黑体"><big><big><p align="center"></big></big><a href="http://cterm.163.net"><img src="banner.gif" width="400" height="60" alt="banner.gif"border="0"></a></font></td>
</tr>
<tr><td width="100%" colspan="2" height="100" align="center" valign="top"><br><p align="center">[<a href="index.htm">回到开始</a>][<a href="12.htm">上一层</a>][<a href="478.htm">下一篇</a>]
<hr><p align="left"><small>发信人: cloudsky (晓舟·轩辕明月), 信区: Security <br>
标 题: 关于攻击的讨论(2) <br>
发信站: 武汉白云黄鹤站 (Sat Jan 30 20:41:58 1999) , 站内信件 <br>
<br>
>This oshare.c code may have crashed our Checkpoint Firewall-1, version 3.0b, <br>
>Build Number: 3083. (Sun Sparc, Solaris 2.5.1) <br>
<br>
[snip] <br>
<br>
Little modification in the source. For example... <br>
<br>
---------------------------------------------- <br>
ip->ihl = 22; <br>
ip->frag_off = htons( -16383 ); <br>
---------------------------------------------- <br>
<br>
Compile, and send heaps of packets ('./oshare x.x.x.x 300' for example) to <br>
local Windows 98/NT box. It should freeze (literally) while packets are <br>
travelling. It recovers after the 'attack' is finished (shouldn't be a big <br>
problem to leave a process in the background that will send packets forever). <br>
<br>
This was tested against Windows 98 and Windows NT 4.0 ( 2 Workstations and <br>
1 Server - all with SP4 applied, no post SP4 hotfixes). <br>
<br>
*Please*, don't mail me with "It didn't work for me!" - that's why I post <br>
it here, so people can test & make summaries. Play around with source, you <br>
can get interesting effects (and responses from router :). Don't try to <br>
flood NT boxes outside internal network - packets won't get out (they <br>
didn't for me - others could have different results). <br>
<br>
It will also affect HP-UX (tested against 10.20), but I didn't get more <br>
than "jumping mouse" effect. Load is higher, but machine is functional. <br>
<br>
Linux (2.0.36 and 2.2.0-pre4) was not affected. <br>
<br>
(final note: program was compiled and 'initiated' on linux box w/ <br>
2.2.0-pre4 kernel) <br>
<br>
The cause that it doesn't work well is thought to be here. <br>
<br>
1) A difference in the version of OS. <br>
It works with ja, and it may not work with en. <br>
<br>
2) Modification of the code. <br>
When it was rewritten, my acquaintance's machine crashed a part. <br>
This modification makes the cause of the bug much more vague, <br>
Only, by 100 packet. <br>
<br>
'send_oshare_packet' <br>
ip->ihl = rand() % 16; <br>
ip->tot_len = rand() % 0xffff; <br>
<br>
On Mon, 25 Jan 1999, DEF CON ZERO WINDOW wrote: <br>
<br>
<SNIPPED WHOLE MESSAGE> <br>
tested on a linux 2.2.0-pre9 machine and it's reporting bad packets but <br>
nothing more <br>
<br>
win98 reboots <br>
<br>
<br>
-- <br>
我问飘逝的风:来迟了? <br>
风感慨:是的,他们已经宣战。 <br>
我问苏醒的大地:还有希望么? <br>
大地揉了揉眼睛:还有,还有无数代的少年。 <br>
我问长空中的英魂:你们相信? <br>
英魂带着笑意离去:相信,希望还在。 <br>
</small><hr>
<p align="center">[<a href="index.htm">回到开始</a>][<a href="12.htm">上一层</a>][<a href="478.htm">下一篇</a>]
<p align="center"><a href="http://cterm.163.net">欢迎访问Cterm主页</a></p>
</table>
</body>
</html>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -