Security Basics mailing list archives

Re: Cisco Workaround


From: igenge2 () csc com au
Date: Thu, 24 Jul 2003 15:03:11 +0800

Hello Doug,

I don't think you have to put all the access-list in.  I believe that
the hack requires a certain combination of packets to the four ports,
so leaving one or two of them open should still prevent the hack.

Firstly, remember that these are IP protocols we are referring to, not 
TCP/UDP ports.  Secondly, we have confirmed that the DoS can be performed 
using any one of the protocols.  So if, for example, you block three of 
the protocols and leave protocol 53 open you are still toast.

Ian Genge
__________________________________________________
Senior Network Engineer
CSC


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: