Home » Network Security » 

5 Top security flaw found in corporate networks

view pageView Page commentShow all comments | commentPost your comment

u forgot about the ICMP reply on firewalls that can help in a DrDoS (distributed reflective denial of services) attack upon someone else when a TCP syn bit has been send with a spoofed source IP header. This makes the firewall send a TCP rst or TCP ack/syn bit to a unknown host and thus constribute in a DrDoS attack without administrators even knowing what is going on..

so switch of your ICMP reply and drop these packets on your firewall as standard policy! ;)

greets

May
2/22/2005 3:17:27 PM - NL  | commentreply

Display Name (shown):

Your E-mail Address (hidden):

Enter what you see here:

Browser IP (security):

38.103.63.17 US « Click to verify

Mail this pageMail this page