Ping of death

A denial-of-service attack that sends a malformed, oversized ICMP echo request in fragments, so reassembly overflows a buffer and crashes an unpatched system.

The ping of death is a denial-of-service attack that abuses ICMP echo requests, the messages the ping utility sends. An IPv4 packet has a maximum size of 65,535 bytes, but fragmentation lets an attacker send pieces whose combined length exceeds that limit once they are reassembled. A vulnerable network stack copies the reassembled data into a buffer sized for a legal packet, overflows it, and the system crashes, hangs or reboots. The attack was widely reported in the mid-1990s, until operating systems were patched to validate fragment sizes.

The distinction candidates commonly confuse is between attacks that break a target with a malformed packet and attacks that exhaust it with volume. The ping of death and the teardrop attack, which sends overlapping fragments, belong to the first group: a single crafted packet can be enough. The smurf attack and fraggle attack use broadcast amplification, and a SYN flood exhausts connection state, which puts all three in the second group. The defences differ accordingly: patching and dropping malformed fragments at the firewall for the first group, rate limiting and filtering for the second.

Exam relevance: a scenario describing an oversized ping that crashes a host is likely to point to the ping of death. Candidates are expected to identify it as a malformed-packet attack and patching as the primary fix.