SG-1.IMS.IDEAS.GD-AIS.COM 08/24/04:21.00 system check (fwd)

Merton Campbell Crockett <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
I spotted this set of entries in my "hourly" log file synopsis and thought 
it might be of interest.

I use the BSD/OS IPFW Facility, a firewall toolkit developed by BSDi.  
The items of interest are the packet fragments with "Don't Fragment" set
that were rejected by pre-input rule 02.  Since developing the IPFW rules
three years ago, this is the first instance of detecting a fragmented
"Don't Fragment" packet.

As all of the other ports are associated with Microsoft vulnerabilites, I 
assume that the fragmentation was intended to trigger a vulnerability in 
IIS.

Merton Campbell Crockett


---------- Forwarded message ----------
Date: Tue, 24 Aug 2004 21:00:01 -0700 (PDT)
From: "WAVE (SG-1) Administrator" <[email protected]>
To: [email protected]
Subject: SG-1.IMS.IDEAS.GD-AIS.COM 08/24/04:21.00 system check


Security Violations
=-=-=-=-=-=-=-=-=-=
[...]
Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02    61.149.95.79 ->     192.73.3.83  D  frag @ 1472
Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02    61.149.95.79 ->     192.73.3.83  D  frag @ 1472
Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
[...]
Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 34    61.149.95.79 ->     192.73.3.83  D  TCP  3627 ->  1433 S      
Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 32    61.149.95.79 ->     192.73.3.83  D  TCP  2984 ->  1025 S      
Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 34    61.149.95.79 ->     192.73.3.83  D  TCP  3259 ->  6129 S      
Aug 24 18:00:51 SG-1 ipfwlog[123]: 04/08/24 18:00:51 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
Aug 24 18:00:57 SG-1 ipfwlog[123]: 04/08/24 18:00:57 !I 34    61.149.95.79 ->     192.73.3.83  D  TCP  3627 ->  1433 S      
Aug 24 18:00:57 SG-1 ipfwlog[123]: 04/08/24 18:00:57 !I 32    61.149.95.79 ->     192.73.3.83  D  TCP  2984 ->  1025 S      
Aug 24 18:00:58 SG-1 ipfwlog[123]: 04/08/24 18:00:58 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
Aug 24 18:01:12 SG-1 ipfwlog[123]: 04/08/24 18:01:12 !I 02    61.149.95.79 ->     192.73.3.83  D  frag @ 1472
Aug 24 18:01:12 SG-1 ipfwlog[123]: 04/08/24 18:01:12 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
[...]
Aug 24 18:01:40 SG-1 ipfwlog[123]: 04/08/24 18:01:40 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   
[...]
Aug 24 18:02:32 SG-1 ipfwlog[123]: 04/08/24 18:02:32 !I 02    61.149.95.79 ->     192.73.3.83  D  frag @ 1472
Aug 24 18:02:32 SG-1 ipfwlog[123]: 04/08/24 18:02:32 !I 02    61.149.95.79 ->     192.73.3.83  DM TCP  3662 ->    80    A   


-- 
BEGIN:				vcard
VERSION:			3.0
FN:				Merton Campbell Crockett
ORG:				General Dynamics Advanced Information Systems;
				Intelligence and Exploitation Systems
N:				Crockett;Merton;Campbell
EMAIL;TYPE=internet:		[email protected]
TEL;TYPE=work,voice,msg,pref:	+1(805)497-5045
TEL;TYPE=work,fax:		+1(805)497-5050
TEL;TYPE=cell,voice,msg:	+1(805)377-6762
END:				vcard

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.