[ipv6hackers] Article: Using IPv6 atomic fragments for a denial-of-service attack

Fernando Gont fgont at si6networks.com
Wed Mar 22 18:07:51 CET 2017


Folks,

FYI:

* Part I: "How a single ICMPv6 packet can cause a denial-of-service
attack"
(<http://searchsecurity.techtarget.com/tip/How-a-single-ICMPv6-packet-can-cause-a-denial-of-service-attack>)

* Part II: "Using IPv6 atomic fragments for a denial-of-service attack"
(<http://searchsecurity.techtarget.com/tip/Using-IPv6-atomic-fragments-for-a-denial-of-service-attack>)


FWIW, this functionality has been removed from the RFC2460bis effort,
and generation "deprecated" in RFC8021... although there's no Std track
document saying you should not generate or react to these packets.

Thanks!

Cheers,
-- 
Fernando Gont
SI6 Networks
e-mail: fgont at si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492






More information about the Ipv6hackers mailing list