[Dshield] Source Quench?

Stephane Grobety security at admin.fulgan.com
Fri Aug 8 12:16:50 GMT 2003


KJ> 08/08/2003 13:30:35.880 ICMP packet dropped 213.197.151.250, 4, WAN
KJ> 212.213.xxx..x, DMZ Source Quench, Code: 0
KJ> What the heck is going on?

Apparently, it's a source quench message (duh!). This ICMP message is
sent from one gateway to the other to tell it that it is overloaded
and that it should slow down the sending of IP packets. It's different
from the NACK packet that might be sent from one final host to another
because it's only used between routers (gateways).

A form of attack called "Super source quench". See "http://www.zockbar.de/jargon/html/entry/super-source-quench.html"

P.S. Google is your friend...


Good luck,
Stephane




More information about the list mailing list