Jump to content

Reflector router

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Postcard Cathy (talk | contribs) at 23:14, 9 May 2009. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Another common DoS (Denial of Service) attack is when an attacker sends a flood of ICMP messages to a reflector or sets of reflectors typically a router using a victim's source IP address in the ICMP echo messages.

The attacker changes the ICMP origin address to the address of the actual victim router device or devices.

The reflector routers then innocently reply to the echo messages sending the replies to the victim router device or devices.

In many cases, the source “spoofed” address is a directed broadcast address allowing the attack to target a network segment instead of a specific host.

Using a large number of reflector routers will create a huge volume of ICMP echo replies to be sent to the victim network causing a DoS (Denial of Service).