ICMP Type:8 Code:137

mutiger_jh_at_yahoo.com
Date: 10/28/05

  • Next message: PatInTheHat: "RE: troj_cryt.u detected"
    Date: 28 Oct 2005 03:12:09 -0000
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) We have been seeing a good number of ICMP - echo requests coming in bursts having a code of 137 in the last couple of days. The burst do not last long but are sometimes preceeded by a traceroute. No other traffice follows from the source hosts. There is no payload in the packets. My research into what or why this is happening has turned up nothing.

    Has any one heard of any attacks or recon using this code?


  • Next message: PatInTheHat: "RE: troj_cryt.u detected"