Smurf attack

A denial-of-service attack that sends ICMP echo requests to a network's broadcast address, forging the victim as the source, so every host on that network replies to the victim.

A smurf attack floods a victim with ping replies it never asked for. The attacker sends ICMP echo requests to the directed broadcast address of an intermediate network, with the victim’s IP address forged as the source. If the router delivers the broadcast, every host on that network answers the echo request, and all of those replies go to the victim. One packet can produce as many replies as there are responding hosts, making the smurf attack an early example of combined reflection and amplification.

It is easily confused with two neighbours. The fraggle attack uses the same broadcast trick with UDP services instead of ICMP. The ping of death also uses ICMP, but sends a single malformed, oversized packet to crash the target rather than flooding it. Smurf attacks are now largely historical: RFC 2644 made not forwarding directed broadcasts the expected default for routers, hosts can be configured to ignore broadcast pings, and ingress filtering (RFC 2827) can block forged source addresses at network edges. The spoofing pattern lives on in distributed denial of service.

Exam relevance: a scenario that combines ICMP, a broadcast address and a spoofed source is likely to describe a smurf attack. Candidates are expected to tell it apart from fraggle (UDP) and ping of death (one malformed packet).