summaryrefslogtreecommitdiff
path: root/informationals/teso-i0005.txt
diff options
context:
space:
mode:
Diffstat (limited to 'informationals/teso-i0005.txt')
-rw-r--r--informationals/teso-i0005.txt35
1 files changed, 35 insertions, 0 deletions
diff --git a/informationals/teso-i0005.txt b/informationals/teso-i0005.txt
new file mode 100644
index 0000000..eda8329
--- /dev/null
+++ b/informationals/teso-i0005.txt
@@ -0,0 +1,35 @@
10005 2000/01/22 Ascend ISDN Router DoS vulnerability (old UDP echo problem)
2
3==== TESO Informational =======================================================
4This piece of information is to be kept confidential.
5===============================================================================
6
7Description ..........: Ascend ISDN Router DoS vulnerability
8Date .................: 2000/01/22 21:00
9Author ...............: scut
10Publicity level ......: known
11Affected .............: unfirewalled Ascend ISDN Routers, for example Ascend
12 Pipeline 50 routers
13Type of entity .......: Router
14Type of discovery ....: denial of service attack
15Severity/Importance ..: interesting
16Found by .............: hendy and scut
17
18Information ===================================================================
19
20A standard Ascend ISDN router has the UDP echo port open. By spoofing the
21source IP address as the destination IP address of the router and sending a UDP
22packet to the router the router will keep the packet within it's internal
23packet table forever. However this is a very old denial of service attack, but
24it has some nice effects here.
25
26For example by sending packets of 500 bytes length you can constantly increase
27the generic router delay time from 0 ms to up to 800 ms. After that the router
28packet table is completely overflowed and the router is inoperational. In this
29state the only thing that will help is a hard reset of the router.
30
31This is just the old echo/echo UDP link problem, but still living very happily
32in any Ascend ISDN router.
33
34===============================================================================
35