Teardrop attack
A denial-of-service attack that sends IP fragments with overlapping offsets, crashing hosts whose reassembly code mishandles the overlap. The known flaws have long been patched.
A teardrop attack targets the way a host rebuilds fragmented IP packets. An oversized packet is split into fragments, each carrying an offset that says where its data belongs. The attacker crafts fragments whose offsets overlap in a way the receiving code does not expect, for example a second fragment that starts and ends inside the first. On systems with the flaw, the reassembly routine miscalculated the length, and the result was a crash, a hang or a reboot. The attack became public in 1997 and affected several operating systems of that period; the flaws it relied on have long been fixed.
It belongs to a family of malformed-packet attacks that exploit implementation bugs rather than overwhelm capacity. The ping of death also abuses fragmentation, but by reassembling into a packet larger than IPv4 permits, while a smurf attack is a reflection flood that depends on volume. The defences are patching, and firewalls or intrusion prevention systems that discard malformed fragments.
Exam relevance: questions in this area tend to give the mechanism and ask for the attack’s name. Overlapping fragments point to teardrop, an oversized reassembled packet to ping of death, and forged broadcast echo requests to smurf. Candidates are expected to see all three as denial-of-service attacks, and patching as the main defence against the first two.