tag:blogger.com,1999:blog-9099779.post3068424375228632629..comments2024-03-23T23:09:17.426+01:00Comments on StalkR's Blog: CVE-2010-2529 ping infinite loopStalkRhttp://www.blogger.com/profile/15113480981262771031noreply@blogger.comBlogger6125tag:blogger.com,1999:blog-9099779.post-66878460604403895662010-08-07T03:54:41.192+02:002010-08-07T03:54:41.192+02:00maybe your firewall/gateway/isp is dropping packet...maybe your firewall/gateway/isp is dropping packets with optionsAnonymousnoreply@blogger.comtag:blogger.com,1999:blog-9099779.post-50657921600200509552010-08-02T03:51:35.867+02:002010-08-02T03:51:35.867+02:00Dear StalkR,
Sorry for disturbing you again.
I use...Dear StalkR,<br />Sorry for disturbing you again.<br />I used sniffer tool to sniff packets when I ping stalkr.net. I didn't see any response packets from stalkr.net to my host. To my understanding of your article, there should be two reasonable when doing "ping stalkr.net" action.<br />case 1(vulnerable case):<br />I can sniff the response packets and the packets cause my ping to infinite loop.<br />case 2(non-vulnerable case):<br />I can sniff the response packets but the packets doesn't cause my ping to infinite loop.<br /><br />No meter what cases, I should see the response packets but I didn't. Is there any thing wrong with my concept?Shanghttps://www.blogger.com/profile/03341401275008538116noreply@blogger.comtag:blogger.com,1999:blog-9099779.post-59836393375793007372010-07-28T13:10:12.329+02:002010-07-28T13:10:12.329+02:00Hello Shang, I checked the Scapy script is running...Hello Shang, I checked the Scapy script is running well. If it doesn't show any ping reply and does not hang with 100% CPU, it means your version of ping is not vulnerable/up-to-date.StalkRhttps://www.blogger.com/profile/15113480981262771031noreply@blogger.comtag:blogger.com,1999:blog-9099779.post-78199362585838282542010-07-28T10:35:49.341+02:002010-07-28T10:35:49.341+02:00Thank you for sharing.
BTW, I want to try to "...Thank you for sharing.<br />BTW, I want to try to "ping stalkr.net", can you run the Scapy script again? THX.Shanghttps://www.blogger.com/profile/03341401275008538116noreply@blogger.comtag:blogger.com,1999:blog-9099779.post-22836015128628564752010-07-25T09:41:29.445+02:002010-07-25T09:41:29.445+02:00Nice paper. ThanksNice paper. ThanksRootBSDhttp://www.r00ted.comnoreply@blogger.comtag:blogger.com,1999:blog-9099779.post-17260619555761044172010-07-25T08:56:23.202+02:002010-07-25T08:56:23.202+02:00Interesting vulnerability :)
Thank you for sharing...Interesting vulnerability :)<br />Thank you for sharing.Gu1http://gu1.aeroxteam.frnoreply@blogger.com