<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Land Attack - web server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563068#M605367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check with "show capture NAME detail" what mac addresses are indicated as source and destination. This looks to me like a packet looping and not typical LAND attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that on TCP level it's SAME exact packet - based on ISN &lt;STRONG&gt;818099150&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Dec 2010 13:07:46 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2010-12-02T13:07:46Z</dc:date>
    <item>
      <title>Land Attack - web server</title>
      <link>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563067#M605366</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a web server on our inside network behind our ASA that's "talking" to itself from it's internal IP to it's NAT IP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1: 14:09:02.316344 172.16.0.166.51676 &amp;gt; 1.2.3.4.80: S 818099150:818099150(0) win 8192 &amp;lt;mss 1460,nop,wscale 8,nop,nop,sackOK&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2: 14:09:05.318953 172.16.0.166.51676 &amp;gt; 1.2.3.4.80: S 818099150:818099150(0) win 8192 &amp;lt;mss 1460,nop,wscale 8,nop,nop,sackOK&amp;gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The vendor is attempting to allow an external session the ability to download a PDF file from the server - and the Land Attack block is preventing that from occurring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web server vendor is insisting that this should be allowed.&amp;nbsp; I'm not in agreement, but I don't know enough about this issue to argue that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this needs to be allowed - is there a way to do so on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563067#M605366</guid>
      <dc:creator>iholdings</dc:creator>
      <dc:date>2019-03-11T19:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Land Attack - web server</title>
      <link>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563068#M605367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check with "show capture NAME detail" what mac addresses are indicated as source and destination. This looks to me like a packet looping and not typical LAND attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that on TCP level it's SAME exact packet - based on ISN &lt;STRONG&gt;818099150&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 13:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563068#M605367</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-12-02T13:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Land Attack - web server</title>
      <link>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563069#M605368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the sho cap details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh cap capi detail | in 1.2.3.4"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 13:58:40.390192 0022.5560.3601 0013.c480.5e0b 0x0800 66: 172.16.0.166.56581 &amp;gt; 1.2.3.4.80: S [tcp sum ok] 2272504169:2272504169(0) win 8192 &lt;MSS 1460=""&gt; (DF) (ttl 127, id 27965) &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 13:58:43.390833 0022.5560.3601 0013.c480.5e0b 0x0800 66: 172.16.0.166.56581 &amp;gt; 1.2.3.4.80: S [tcp sum ok] 2272504169:2272504169(0) win 8192 &lt;MSS 1460=""&gt; (DF) (ttl 127, id 27966) &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 13:58:49.391825 0022.5560.3601 0013.c480.5e0b 0x0800 62: 172.16.0.166.56581 &amp;gt; 1.2.3.4.80: S [tcp sum ok] 2272504169:2272504169(0) win 8192 &lt;MSS 1460=""&gt; (DF) (ttl 127, id 27973)&lt;/MSS&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess this shows the same MAC for both source and destination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 19:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563069#M605368</guid>
      <dc:creator>iholdings</dc:creator>
      <dc:date>2010-12-02T19:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Land Attack - web server</title>
      <link>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563070#M605369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed same source and destination mac address shows that packet is not looping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the message exactly in the ASA logs&amp;nbsp; and if you could put things in perspective (topology etc).IP addresses involve don't make much sense to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In anyway there is no way to disable the LAND attack check in code, but there were instances where it was printed out without need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsl96584"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsl96584&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 22:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/land-attack-web-server/m-p/1563070#M605369</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-12-02T22:58:57Z</dc:date>
    </item>
  </channel>
</rss>

