Re: traceroute-like tool for UDP or TCP packet

From: Edward Rustin (ed_at_well.com)
Date: 08/21/03

  • Next message: David Nichols: "Re: CSMA/CD"
    Date: Thu, 21 Aug 2003 09:36:34 -0700 (PDT)
    To: some guy <someguy_555@hotmail.com>
    
    

    On Thu, 21 Aug 2003, some guy wrote:

    > Linux uses UDP packets to traceroute, not ICMP packets like windows does.
    > Hope that helps,
    > -Scott
    >

    Not really.... an ICMP packet is a type of UDP packet. Basicly traceroute
    works by sending a series of ICMP ECHO requests with increacing TTLs (time
    to live - how many hops the packet can travel before it dies and aPacket
    Timeout error is sent). A ping is also just a ICMP ECHO message, just with
    a defualt TTL, rather than a series of increasing TTLs.

    >
    > >From: "Kent James" <kent1@caspia.com>
    > >To: <security-basics@securityfocus.com>
    > >Subject: traceroute-like tool for UDP or TCP packets
    > >Date: Wed, 20 Aug 2003 22:30:21 +0500
    > >
    > >One of the local ISPs is having trouble getting DNS information from
    > >Easydns. I suspect they have a misconfigured firewall or other security
    > >block in their system. I can ping and traceroute the DNS servers but get no
    > >response from UDP or TCP packets.
    > >
    > >Is there a tool that works like traceroute, only shows the route for TCP or
    > >UDP packets instead of the ICMP packets that traceroute uses?
    > >

    Make sure that the IS isn't blocking traffic coming back from a port 53,
    or too a port 53 (make sure both UDP and TCP is open since a large DNS
    relpy (over 1500 bytes I =think=) will get replied to oever TCP

    Edward Rustin
    Directory of Security, OnlineGuardians.org

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: David Nichols: "Re: CSMA/CD"

    Relevant Pages

    • Re: Traceroute anomaly
      ... source of this traceroute - in C, of course - on the system. ... on the packet path over the IP network. ... is not open on the destination IP node. ... The ICMP packet contains the address of the receiving ...
      (comp.dcom.sys.cisco)
    • Re: traceroute-like tool for UDP or TCP packet
      ... an ICMP packet is a type of UDP packet. ... > works by sending a series of ICMP ECHO requests with increacing TTLs (time ... Also, I think you meant "an ICMP packet is a type of IP packet", rather ... than "an ICMP packet is a type of UDP packet". ...
      (Security-Basics)
    • Re: ICMP type 3, an attack?
      ... ICMP packet not include ... whole packet above were crafted by ... I have tried traceroute. ... both on different networks. ...
      (comp.os.linux.security)
    • Re: Neotrace program snoops on me
      ... >> DNS servers. ... A client starts a traceroute to some computer. ... the TTL field in the IP packet by one. ... > those hops from McAfee's database. ...
      (alt.computer.security)
    • Re: It is a astonishing circumstance about trace route....
      ... >and the TraceRoute didn't stop when ICMP packet arrive at destination. ... the windoze version of traceroute uses ping. ... same host you reported the problem with, as this _is_ a dynamic address. ... TTL of zero. ...
      (comp.os.linux.networking)