3.3. ICMP Land Attack
This is another Layer-3 attack where the ICMP ping request packet is spoofed with destination IP host/port ad-dress same as source’s. When a barrage of such Land attack packets were sent the host becomes busy in replying to itself and results in system lockup. This vulnerability was found in Windows XP with SP2 service pack and also Windows Server 2003 with firewall turned off. These systems are found vulnerable for the LAND attack, which caused a temporary Denial of Service (DoS) that lasts for 15 to 30 seconds. In case of windows Server 2003 not only the server but also all workstations on the network froze [15]. A similar testing was done on Windows XP, Vista and Apple’s Leopard OS, where it was found that the Windows Vista has crashed at ICMP Land attack load of 30 Mbps [16].