Re: ip_defrag is broken (was: Re: test12 lockups -- need feedback)

From: Tom Leete (tleete@mountain.net)
Date: Fri Dec 15 2000 - 04:22:31 EST


"Mohammad A. Haque" wrote:
>
> I do the following....
>
> sudo modprobe iptable_nat
>
> Module Size Used by
> iptable_nat 17440 0 (unused)
> ip_conntrack 19808 1 [iptable_nat]
> ip_tables 12320 3 [iptable_nat]
>
> Oops start flying by when I access via NFS.
>
> If you need the actual Oops messages we're gonna have to get someone
> who can setup a serial console.
>

see my post of day before yesterday under the nfs thread for serial
console+kdb of this.

I also posted a simpler one under this thread of a fragmented ping attack
which is executable by any user on a peer.
# ping -c 100 -s 1470 -f <t12-host>
works fine;
$ ping -c 1 -s 1478 <t12-host>
crashes the target every time.

Tom
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Fri Dec 15 2000 - 21:00:31 EST