Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Sessions Resource Exhaustion |
|---|---|
| Date: | Sat, 13 Oct 2007 09:27:34 -0400 |
Hello, On Thu, 11 Oct 2007 09:14:02 -0700 "Ravi Chunduru" <ravi.is.chunduru@gmail.com> wrote:
using simple tools such as hping2 and others, i am able to exhaust session resources in some firewall and IPS devices. some firewalls and IPS devices addressing small business market segments seems to be supporting maximum of 10000 sessions. these devices are not allowing any new connections if all 10000 sessions are used up. can i say that these devices are vulnerable to simple DoS attacks?
In fact, you've to take in consideration a simple thing, a security device (and a specific model) is build for a specific job, this is why there're so differents models inside a same company. To exceed the limits of designs is not a proof that a device is not good for it (aka vulnerable), just that it is not ready for that. Best regards, Jean-philippe. ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Sessions Resource Exhaustion, Ravi Chunduru |
|---|---|
| Next by Date: | RE: Sessions Resource Exhaustion, Ahsan Khan |
| Previous by Thread: | RE: Sessions Resource Exhaustion, Nelson Brito |
| Next by Thread: | RE: Sessions Resource Exhaustion, Srinivasa Addepalli |
| Indexes: | [Date] [Thread] [Top] [All Lists] |