Re: Best way to filter "Nachi pings"?

From: Kris Kennaway (kris_at_obsecurity.org)
Date: 10/27/03

  • Next message: Richard Bejtlich: "Recent use of Fragroute"
    Date: Mon, 27 Oct 2003 01:34:35 -0800
    To: Jarkko Santala <jake@iki.fi>
    
    
    

    On Mon, Oct 27, 2003 at 11:06:52AM +0200, Jarkko Santala wrote:
    > On Mon, 27 Oct 2003, Kris Kennaway wrote:
    >
    > > On Mon, Oct 27, 2003 at 12:31:46AM -0700, Brett Glass wrote:
    > > > We're being ping-flooded by the Nachi worm, which probes subnets for
    > > > systems to attack by sending 92-byte ping packets. Unfortunately,
    > > > IPFW doesn't seem to have the ability to filter packets by length.
    > > > Assuming that I stick with IPFW, what's the best way to stem the
    > > > tide?
    > >
    > > Block all ping packets? Most security-conscious admins do this
    >
    > D'oh? I like ping very much and it would make me very sad indeed if I
    > couldn't ping my boxes to solve possible network problems along the way. I
    > fail to see the security problem and possible DoS issues could be solved
    > by using limiting of sort.

    The security and DoS concerns are really kind of obvious.

    No-one has a gun to your head though, so I fail to see why you're
    complaining that someone else might do this on their own network.

    > Definitely this block-all approach is not sane, its like if someone
    > complains about NFS being broken you'd say disable it. Filtering packets
    > by length on the other hand is a very nice feature to have.

    As it happens, ipfw[2] does this anyway.

    Kris

    
    



  • Next message: Richard Bejtlich: "Recent use of Fragroute"

    Relevant Pages

    • Re: A Can Ping B, But B Cannot Ping A?
      ... Network problems. ... The workgroup is named "303" ... Machine A can ping machine B, ... Do you have file and printer sharing enabled as a firewall exception on B ...
      (microsoft.public.windowsxp.general)
    • Re: Smoothwall
      ... > reports that it's pingable from the Internet. ... Ping is not a bad thing -- GRC at times can be cia-level paranoid. ... people) if ping is limited to prevent a DoS. ... You should log in as root to the smoothwall machine itself and then use ...
      (comp.security.firewalls)
    • Re: End to end test performance
      ... I have a DOS application running on a Win98 box with MS LANMAN network. ... the ping log report. ...
      (microsoft.public.windowsxp.general)
    • Re: Kernel error?? Hacked?? Bad NIC??
      ... No, no packet filtering. ... I can preform ping from this ... ntpd is complaining about the kernel phase-lock. ...
      (FreeBSD-Security)
    • Re: Best way to filter "Nachi pings"?
      ... I like ping very much and it would make me very sad indeed if I ... > The security and DoS concerns are really kind of obvious. ... all ping packets to improve security is nothing more than security through ... > complaining that someone else might do this on their own network. ...
      (FreeBSD-Security)