Understanding a DOS denial of service attack?
Help me understand a teardrop attack?
I am doing a cyber security project for college on a wireshark pcap file which has a short example of a teardrop attack. Can someone help me understand what Im looking at so I can understand exactly what is happening in this attack. Im looking for how the frame is extended and if you can explain how it should be if it was not altered. Thank you
here is the link to the pcap file to look at if you want to see (You need wire shark):
https://wiki.wireshark.org/SampleCaptures?action=A...
There is a line in frame 8 that says reassembled in frame 9.
In frame 9 heres the info that is pertinent:
Frame Number: 9
Frame Length: 38 bytes (304 bits)
Capture Length: 38 bytes (304 bits)
Total Length: 24
Fragment offset: 24
Protocol: UDP (17)
[2 IPv4 Fragments (28 bytes): #8(36), #9(4)]
Length: 36 (bogus, payload length 28)
[Expert Info (Error/Malformed): Bad length value 36 > IP payload length]
[Checksum: [missing]]
[Checksum Status: Not present]
[Stream index: 1]
[Timestamps]
Data (20 bytes)