RE: About ping request?

From: Ian P. Christian (pookey@pookey.co.uk)
Date: 05/27/02


From: "Ian P. Christian" <pookey@pookey.co.uk>
To: "'Chris Shepherd'" <chriss@whstuart.com>, "'Jens Benecke'" <mail-020524@jensbenecke.de>, "'Patrick Morris'" <pmorris@wilshire.com>
Date: Mon, 27 May 2002 21:42:57 +0100


http://www.phrack.com/show.php?p=49&a=6

HTH

--

----------------------------------------------------------------- Ian Christian E-Mail: pookey at pookey dot co dot uk President and Tech Officer for Termisoc PGP Key ID: 0xD09C10ED ----------------------------------------------------------------- GCC d s: a-- C+++ UL++ P+ !E W++ N+ w M-- PS PGP+ t+ e>++ h+ z**

> -----Original Message----- > From: Chris Shepherd [mailto:chriss@whstuart.com] > Sent: 27 May 2002 19:09 > To: Jens Benecke; Patrick Morris > Cc: focus-ms@securityfocus.com > Subject: Re: About ping request? > > > At 01:33 PM 5/24/2002 +0200, Jens Benecke wrote: > >Please elaborate. I don't see what 'nastiness' can be hidden > inside an > >ICMP echo-request packet, unless your TCP/IP stack is really severely > >broken. > > I believe he's referring to the various trojans that listen > for a specific > sized ping packet before activating. > > > Chris Shepherd > > > > >