Cisco warns of ICMP-based attacks on routers

Opinion
Apr 13, 20052 mins

Latest Cisco news.

Cisco warns of ICMP-based attacks on routers

By Phil Hochmuth

Network World Fusion, 04/13/05

In its second IOS security bulletin in a week, Cisco warned that a common management protocol used on the Internet could be used to launch denial-of-service attacks against Cisco routers and other IP-based gear.

The security advisory warns of potential attacks based on Internet Control Message Protocol (ICMP), which could cause an IOS-based device to become inaccessible. The Cisco advisory is based on a bulletin posted by the U.K.-based National Infrastructure Security Co-ordination Centre, which references a document published on the IETF’s Web site describing how ICMP can be used to launch DoS attacks against TCP traffic in general.

ICMP is a protocol used with TCP/IP to alert devices of network outages and report diagnostic information to peer devices on an IP network. According to the IETF document , an attacker could send certain ICMP “hard error” messages to a device running TCP, which would cause the device to reset a TCP connection or to reduce the throughput of a TCP connection. If such ICMP messages are sent repeatedly, the device could become unavailable on the network. The IETF document also outlines another DoS attack method which uses Path Maximum Transmission Unit Discovery (PMTUD), a mechanism in ICMP for handling error messages.

To read this story in full, please go to:

https://www.nwfusion.com/news/2005/0413icmp.html?nl