Flood ping 2004-06-10 - By Gurugunti, Mahesh
Back In a normal situation when a machine pings another host from valid (return address to itself) , the pinged machine sends the acknowlegement back and it in turn gets acknowlegement from source machine. So the sync/ack/n(ack) conversation/session is completed successfully and the connection closes. But if the source ping machine pings another machine with a "false" return address then , then pinged machine sends the acknowledgement but never gets any response for this(since the return address is not a valid address) . So the session is kept open. When 100s and 1000s of such pings are sent then there will lot of sessions open on destination machine and it eventually brings down that machine (or whichever pingable device). Mahesh
-- --Original Message-- -- From: Harry Hambi [mailto:harry.hambi@(protected)] Sent: Thursday, June 10, 2004 10:15 AM To: valhalla-list@(protected) Subject: Flood ping
Hi all, Can somebody explain what flood ping is, more importantly what it can tell you about your network.
Rgds.
Harry.
http://www.bbc.co.uk/ - World Wide Wonderland
This e-mail (and any attachments) is confidential and may contain personal views which are not the views of the BBC unless specifically stated. If you have received it in error, please delete it from your system. Do not use, copy or disclose the information in any way nor act in reliance on it and notify the sender immediately. Please note that the BBC monitors e-mails sent or received. Further communication will signify your consent to this.
-- -- This message is for the named person's use only. It may contain confidential, proprietary or legally privileged information. No confidentiality or privilege is waived or lost by any mistransmission. If you receive this message in error, please delete it and all copies from your system, destroy any hard copies and notify the sender. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. Nomura Holding America Inc., Nomura Securities International, Inc, and their respective subsidiaries each reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorized to state the views of such entity. Unless otherwise stated, any pricing information in this message is indicative only, is subject to change and does not constitute an offer to deal at any price quoted. Any reference to the terms of executed transactions should be treated as preliminary only and subject to our formal written confirmation.
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859 (See http://iso-8859.ora-code.com)-1"> <TITLE>Flood ping</TITLE>
<META content="MSHTML 6.00.2800.1400" name=GENERATOR></HEAD> <BODY> <DIV><SPAN class=099171614-10062004><FONT face=Arial color=#0000ff size=2>In a normal situation when a machine pings another host from valid (return address to itself) , the pinged machine sends the acknowlegement back and it in turn gets acknowlegement from source machine. So the sync/ack/n(ack) conversation/session is completed successfully and the connection closes.</FONT></SPAN></DIV> <DIV><SPAN class=099171614-10062004><FONT face=Arial color=#0000ff size=2></FONT></SPAN> </DIV> <DIV><SPAN class=099171614-10062004><FONT face=Arial color=#0000ff size=2>But if the source ping machine pings another machine with a "false" return address then , then pinged machine sends the acknowledgement but never gets any response for this(since the return address is not a valid address) . So the session is kept open. When 100s and 1000s of such pings are sent then there will lot of sessions open on destination machine and it eventually brings down that machine (or whichever pingable device).</FONT></SPAN></DIV> <DIV><SPAN class=099171614-10062004><FONT face=Arial color=#0000ff size=2></FONT></SPAN> </DIV> <DIV><SPAN class=099171614-10062004><FONT face=Arial color=#0000ff size=2>Mahesh</FONT></SPAN></DIV> <BLOCKQUOTE> <DIV class=OutlookMessageHeader dir=ltr align=left><FONT face=Tahoma size=2>-- --Original Message-- --<BR><B>From:</B> Harry Hambi [mailto:harry.hambi@(protected)]<BR><B>Sent:</B> Thursday, June 10, 2004 10:15 AM<BR><B>To:</B> valhalla-list@(protected)<BR><B>Subject:</B> Flood ping<BR><BR></FONT></DIV><!-- Converted from text/rtf format --> <P><FONT face=Arial size=2>Hi all,</FONT> <BR><FONT face=Arial size=2>Can somebody explain what flood ping is, more importantly what it can tell you about your network.</FONT> </P> <P><FONT face=Arial size=2>Rgds.</FONT> </P><BR> <P><FONT face=Arial size=2>Harry.</FONT> </P><BR>http://www.bbc.co.uk/ - World Wide Wonderland<BR><BR>This e-mail (and any attachments) is confidential and may contain<BR>personal views which are not the views of the BBC unless specifically<BR>stated.<BR>If you have received it in error, please delete it from your system. <BR>Do not use, copy or disclose the information in any way nor act in<BR>reliance on it and notify the sender immediately. Please note that the<BR>BBC monitors e-mails sent or received. <BR>Further communication will signify your consent to this. </BLOCKQUOTE></BODY></HTML>
<P><FONT SIZE=2 FACE="Arial">-- -- This message is for the named person's use only. It may contain confidential, proprietary or legally privileged information. No confidentiality or privilege is waived or lost by any mistransmission. If you receive this message in error, please delete it and all copies from your system, destroy any hard copies and notify the sender. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. Nomura Holding America Inc., Nomura Securities International, Inc, and their respective subsidiaries each reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorized to state the views of such entity. Unless otherwise stated, any pricing information in this message is indicative only, is subject to change and does not constitute an offer to deal at any price quoted. Any reference to the terms of executed transactions should be treated as preliminary only and subject to our formal written confirmation.</FONT></P>
__ ____ ____ ____ ____ ____ ____ ____ ____ ____ Valhalla-list mailing list Valhalla-list@(protected) https://www.redhat.com/mailman/listinfo/valhalla-list
|
|