Actions
Bug #280
closedFragmentation issue - Ping of death not properly detected
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
Following Scapy payload doesn't trigger an alert in Suricata:send( fragment(IP(dst="192.168.100.35")/ICMP()/("X"*60000)) )
In Snort, it triggers following alert:[**] [123:8:1] (spp_frag3) Fragmentation overlap [**]
[Priority: 3]
03/19-00:21:07.280484 192.168.100.37 -> 192.168.100.36
ICMP TTL:64 TOS:0x0 ID:1 IpLen:20 DgmLen:828
Frag Offset: 0x1CE8 Frag Size: 0x0328
Attached the capture file.
Thx for your support
Files
Actions