IP fragmentation attack: Difference between revisions

Content deleted Content added
m Update reference for Rose Attack explained
IP fragment too small: This is not an exploit itself, just a sign of one, so I adjusted the wording to better explain that.
Line 161:
This exploit occurs when a datagram can not be fully reassembled due to missing data. This can indicate a denial of service attack or an attempt to defeat packet filter security policies.
 
=== IP fragmentFragment tooToo smallSmall ===
AnIf an IP Fragmentfragment Toois Smalltoo exploitsmall it indicates that the fragment is whenlikely intentionally crafted. anyAny fragment other than the final fragment that is less than 400 bytes, indicatingcould thatbe theconsidered fragment istoo likely intentionally craftedsmall. Small fragments may be used in denial of service attacks or in an attempt to bypass security measures or detection.
 
== Fragmentation for evasion ==