📄 473.txt
字号:
Rule:--Sid:473--Summary:This event is generated when an ICMP Redirect Network message wasdetected in network traffic.--Impact:Unknown. Possible system crash, Denial of Service (DoS) for someembedded operating systems.--Detailed Information:Several susceptible IP Stack implementations may result in the systemhanging or crashing when malformed or corrupted ICMP Redirect Network(Type 5, Code 0) packets are sent to them. This vulnerability was firstdiscovered in 1997.Under normal network conditions ICMP Redirect Network packets will occurin a number of situations. One such situation is when a host is on asubnet with more than one router. The host can only have one defaultgateway, and forwards all traffic for networks outside its own subnet tothis gateway. If the default gateway detects that the gateway for thisroute is on the same subnet as the originating host, the default gatewayforwards the packet onto this gateway and sends an ICMP Redirect Networkto the originating host.This funtionality exists primarily to save network administrators fromhaving to keep extensive routing tables on hosts, the host will rememberthe route learned from the ICMP Redirect Network message for a period oftime, and will forward any traffic directly while it has the route inits cache.--Affected Systems: All systems--Attack Scenarios:A malicious user may send corrupted ICMP Redirect Net messages tonetworks in an attempt to crash a system.--Ease of Attack:Simple.--False Positives:Any ICMP Network Redirect will generate an event.--False Negatives:None Known--Corrective Action:Patches for Microsoft Windows NT 4.0 were included in SP4, and alsorelease as a post SP3 fix - teardrop2-fix. Fixes are also available forWindows 95 and various embedded systems.--Contributors:Original rule writer unknownOriginal document author unkownSourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>--Additional References:Microsoft KB, Q154174--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -