case 5-2 Your are asked to check your company\'s configurations to determine if
ID: 3800157 • Letter: C
Question
case 5-2
Your are asked to check your company's configurations to determine if any filters should be built to stop certain ICMPv6 traffic. Your supervvisor ask for a list of ICMPv6 traffic or issurs that are of concern and the reasions why such concerns could be a problem. BUild a list for your supervisior. Include packet types or specific circumstances in which ICMPv6 traffic could compromise netowrk security.
case 5-3
You moved to San Diego to work with a large sport apparael company. Its network grew throuhg various corporate acquistions- it is truly a mix of media, speeds, computers, and applications. Your are not sure if this networks hosts and routers support PMTU Discovery to reduce fragements on the network. Write a brief polan definnifing how you can test this network for PMTU support.
case 5-4
Throught the RFCs, you've notice the intials JBP and the name Jon B. Postel. Access IANA'S website www iana org and serarch for information on Jon Postel. Write a single paragraph defining Jon Postel's effect on the development of IP and related Internet protocols.
Explanation / Answer
5.2
The ICMP packets that are of concern are
1.Destination unreachable message packet
2.Redirect request packet
3.Time Exceeded packet
4.ICMP smruf (The attacker uses a program called Smurf to cause the attacked part of a network to become inoperable)
5.Echo packet request
6.Ping requests
7.fragmentation needed and don't fragment bit set messages
Reason why these packets are of concern:
1. Time exceeded and Destination unreachable messages causes drop in connections.
The ICMP destination unreachable message is generated by a router to inform the source host that the destination unicast address is unreachable.This can be used by attacker to his advantage.
2. ICMP Redirect message can make one host send packets for one connection through another mostly the host or attackers system.
3. By sending ICMP echo packets an attack called as ICMP packet magnification or also known as ICMP Smurf is done. In this attack the entire bandwidth is blocked due to massive echo messages
4. Similar thing is done in ping message causing death of network by ping request packets
5. in Nuke attack a packet is send that cannot be deciphered and handled by the OS resulting in crash and ultimate failure.
6. Echo message can be used in ICMP Ping flood attack too..
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.