To all LANTUG members,

A large number of operating systems and network firmware may be
vulnerable to a newly discovered TCP/IP flaw called the "Ping of Death,"
which overloads and crashes a system by sending excessively large

In a nutshell, it is possible to crash, reboot or otherwise kill a large
number of systems by sending a ping of a certain size from a remote
machine. This is a serious problem, mainly because this can be
reproduced very easily, and from a remote machine, and because the
attacker needs to know nothing about the machine other than its IP
address. Over 18 major operating systems have been found vulnerable. 

Please visit the following website for full details, including operating
systems (including NT 3.51 and possibly NT 4.0), firmware, hardware
(routers, printers, etc.) which are vulnerable, and available patches
and solutions:


Also, PCWEEK published, on Nov 12, 1996, a piece on this problem at
http://www.pcweek.com/news/1111/12mping.html, which means more people
will know how to do it and try it out.

