TechNotes Practice tests

UnixGuyUnixGuy Mod Posts: 4,570 Mod
Hi everybody,

I'm trying to workout the practice questions provided by TechExams forums, and I need your help to get explanations.
Question #7
7. Which of the following attacks is NOT aimed at fragmentation vulnerabilities of the IP stack?

Answer: Smurf Attack.

Isn't the ICMP part of the IP Stack ? Isn't this attack happening due to inherent weakness of TCP/IP stack ?

please help
Certs: GSTRT, GPEN, GCFA, CISM, CRISC, RHCE

Learn GRC! GRC Mastery : https://grcmastery.com 

Comments

  • astorrsastorrs Member Posts: 3,139 ■■■■■■□□□□
    UnixGuy wrote: »
    Hi everybody,

    I'm trying to workout the practice questions provided by TechExams forums, and I need your help to get explanations.



    Isn't the ICMP part of the IP Stack ? Isn't this attack happening due to inherent weakness of TCP/IP stack ?

    please help
    A Smurf Attack isn't taking advantage of fragmentation vulnerabilities; instead it's exploiting the normal behavior of the ICMP echo command and causing a denial-of-service attack against the target.
  • UnixGuyUnixGuy Mod Posts: 4,570 Mod
    astorrs wrote: »
    A Smurf Attack isn't taking advantage of fragmentation vulnerabilities; instead it's exploiting the normal behavior of the ICMP echo command and causing a denial-of-service attack against the target.


    Can you please give me examples of Fragmentation vulnerabilities in IP Stack ?
    Certs: GSTRT, GPEN, GCFA, CISM, CRISC, RHCE

    Learn GRC! GRC Mastery : https://grcmastery.com 

  • astorrsastorrs Member Posts: 3,139 ■■■■■■□□□□
    UnixGuy wrote: »
    Can you please give me examples of Fragmentation vulnerabilities in IP Stack ?
    Have a look at the teardrop attack of "yesteryear" (pretty much useless these days) as it's a good example.
  • UnixGuyUnixGuy Mod Posts: 4,570 Mod
    Thanks icon_cheers.gif

    I need serious review specially Cryptography.
    Certs: GSTRT, GPEN, GCFA, CISM, CRISC, RHCE

    Learn GRC! GRC Mastery : https://grcmastery.com 

Sign In or Register to comment.