ICMP-based attacks, ping scans, the ping of death, and L3 DDoS
IP-based attacks are attacks that focus on layer 3, which is everything related to IP addresses. ARP-based attacks focus on a network device's ARP cache, usually to hijack end-to-end sessions by impersonating the addresses of the target of the attack. We talked about these two types of attacks in Chapter 6, Finding Network-Based Attacks, in the L3 and ARP-based attacks section.
In this section, we will talk about the following attacks:
- Ping scans and layer 3 DDoS
- The ping of death and malformed packets
Let's get to the details.
Ping scans and L3 DDoS
Ping scans can be used for two purposes:
- For network discovery, to identify potential victims
- As a DDoS attack, using ICMP packets to block a network or for loading network devices
A ping scan used for network discovery
For network scanning, we will simply see a scanning pattern from a single source. It will start...