Mailing List Archive

Detect ping.asp
According to NTBUGTRAQ, this ASP is a good DDoS tool :-)
Re: Detect ping.asp [ In reply to ]
Yup...but your wording is I believe suspect - you can't launch
the DoS on an IP by entering parameters that include 127.0.0.1 - that
I believe was only per example ;-)

Thomas

Michel Arboi wrote:
>
> According to NTBUGTRAQ, this ASP is a good DDoS tool :-)
>
> ------------------------------------------------------------------------
> Name: ping_asp.nasl
> ping_asp.nasl Type: Plain Text (text/plain)
> Encoding: quoted-printable
Re: Detect ping.asp [ In reply to ]
Thomas Reinke <reinke@e-softinc.com> writes:

> Yup...but your wording is I believe suspect - you can't launch
> the DoS on an IP by entering parameters that include 127.0.0.1

Right.

Should I write:
The 'ping.asp' CGI is installed. Some versions
allows a cracker to launch a ping flood against your
machine or another by entering (for example) <---
'127.0.0.1 -l 65000 -t' in the Address field.

Or:
allows a cracker to launch a ping flood against your
machine or another by entering
'IpAddr -l 65000 -t' in the Address field. <---