Re: 2000 server solution

From: Tim S. Knight (spu_kcab_at_yahoo.com)
Date: 10/21/03


Date: Tue, 21 Oct 2003 17:35:57 -0000

Leythos <void@nowhere.com> wrote in
news:MPG.19ff274033277197989d6c@news-server.columbus.rr.com:

>> > If the machine responds to a PING it will be found quickly -
>>
>> Laughable. There is nothing wrong with ICMP. Have you ever had the
>> idea that something called Internet Control Message Protocol might be
>> called so for
>> ^ ^ ^ ^
>
> There is no reason for a server to respond to ICMP. You can access the
> features without it. I block ICMP at all clients sites and have never
> had a problem getting to them. It all comes down to understanding the
> platform and security.
>

Sure there is. It's called ICMP type 3, code 4: Fragmentation needed but DF
bit set (ICMP_UNREACH_NEEDFRAG.) ICMP isn't just ping you know.



Relevant Pages

  • Re: Port 3 to Port 1; PROTO=1
    ... icmp 1 ICMP # internet control message protocol ... 0792 Internet Control Message Protocol. ... ICMP doesn't have 'ports', so what you see in the 'source port' is the ...
    (comp.os.linux.security)
  • Re: Re: Verified evasion in Snort
    ... anything other than the first fragment.) ... Internet Control Message Protocol -- ICMP ...
    (Bugtraq)
  • Re: Ok to let all ICMP traffic through firewall?
    ... On Sat, 24 Sep 2005 02:06:07 GMT, Leythos ... > VPN's, we do not allow ICMP with the world as a general rule, just with ... configuration to me. ...
    (comp.security.misc)
  • Re: Ok to let all ICMP traffic through firewall?
    ... On Sat, 24 Sep 2005 02:06:07 GMT, Leythos ... > VPN's, we do not allow ICMP with the world as a general rule, just with ... configuration to me. ...
    (comp.security.firewalls)
  • Re: Ok to let all ICMP traffic through firewall?
    ... On Sat, 24 Sep 2005 02:06:07 GMT, Leythos ... > VPN's, we do not allow ICMP with the world as a general rule, just with ... configuration to me. ...
    (alt.computer.security)

Quantcast