[prev in list] [next in list] [prev in thread] [next in thread] 

List:       dragonidsuser
Subject:    [Dragonidsuser] FRAG-OVERLAP & double traffic
From:       "JiPi DiNis" <jp () webglobe ! ca>
Date:       2005-09-05 18:03:35
Message-ID: 18931.64.86.141.143.1125943415.webglobe () 64 ! 86 ! 141 ! 143
[Download RAW message or body]

Hi,


  I received a bunch of packets in double and dragon generated many
  FRAG-OVERLAP events.

  I took a quick look at the IP headers and all the packets have the 0x40
DF flags set with no Offset 0x00. (40 00)

  Packets received in double are identical.

  Fragmentation always need the MF flag and an offset for reassembly,
right?

  How can packets with the DF flag and no Offset overlap each other?

  Did Dragon generated this because of the double traffic without looking
at the flags or Offset before deciding if they can overwirte themself ?



Thanks,
JP





[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic