RE: UDP packet handling weird behaviour of various operating systems

From: David LeBlanc (dleblancat_private)
Date: Thu Jul 26 2001 - 22:08:00 PDT

  • Next message: Sean Hunter: "Re: UDP packet handling weird behaviour of various operating systems"

    > -----Original Message-----
    > From: Michal Zalewski [mailto:lcamtufat_private]
    
    > > 3. Windows 2000 Server UP. - the system graphs jump from 2%
    > cpu usage
    > > (in a calm evening with no ongoing backups and domain
    > > synchronizations) to approx. 35% and holds it steady.
    
    > Windows are usually impacted by high-ratio packet floods.
    
    Depends on the NIC, the driver, and the OS version. Very old versions of
    NDIS weren't as efficient as more recent versions. Driver quality tends to
    dominate the results.
    
    > I believe you are actually testing link layer performance,
    > PCI bus speed
    > and network cards, not operating systems ;)
    
    And NIC driver.
    
    I've seen this happen more than once - Attacker is fast box tester writes
    flood code on. Victim is some dilapidated system that should have been
    retired. CPU gets pegged on victim, as it has a cheap NIC with bad drivers.
    Person thinks they've found a new exploit. Some NICs work better than
    others, and some drivers work better than others.
    



    This archive was generated by hypermail 2b30 : Thu Jul 26 2001 - 23:08:56 PDT