Fraggle attack

A denial-of-service attack that sends UDP packets with the victim's spoofed source address to a broadcast address, so every responding host floods the victim with replies.

A Fraggle attack is the UDP counterpart of the Smurf attack. The attacker sends UDP packets to a network’s broadcast address, forging the source address so that it is the victim’s. The packets are aimed at simple UDP services, such as echo and character generation, that reply to whatever they receive. Every host that runs those services answers, and the answers go to the victim. One packet becomes many, which is the combination of reflection and amplification behind many denial-of-service attacks.

The distinction from Smurf is essentially the protocol: Smurf uses ICMP echo requests, and Fraggle uses UDP. The defences are the same in kind. Routers can refuse directed broadcasts, and RFC 2644 (1999) made neither receiving nor forwarding them the expected router default. Hosts can disable the unneeded UDP diagnostic services. Networks can apply egress filtering so that packets with source addresses they do not own are dropped, which helps stop their hosts being used in spoofed attacks.

Exam relevance: a scenario is likely to describe a flood of UDP replies from many hosts on one network, which points to Fraggle; the same picture with ICMP points to Smurf. Candidates are expected to link both to spoofing and to broadcast handling.