Security Basics mailing list archives

Re: ICMP [ping]


From: "J. Oquendo" <segment () antioffline com>
Date: Fri, 5 Sep 2003 15:50:45 -0400

http://www.phoneboy.com/fom-serve/cache/530.html

Maybe that'll help didn't look at the start of thread.


-------------------------------------------------------
I don't know, if it was mentioned in one of the other replies, but there
is also a technique known to portscan hosts behind a firewall by
allowing icmp code 3 replies (Port unreachable) using a specially
crafted TTL field.

regards, andreas
------------------------------------------------------

+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
Jesus Oquendo
sil @ disgraced . org
sil @ antioffline . com
segment ... antioffline . com
PGP Fingerprint
39A7 24C6 A9A0 6C67 96CA 0302 F1D3 2420 851E E3D0

http://www.antioffline.com
http://www.politrix.org

You're free. And freedom is beautiful. And, you know, 
it'll take time to restore chaos and order, order out
of chaos. But we will." George W. Bush Washington, 
D.C., April 13, 2003


---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
----------------------------------------------------------------------------


Current thread: