Re: ICMP Type:5, Code:5

From: Brian (brianphillips_at_clara.co.uk)
Date: 06/21/04


Date: Mon, 21 Jun 2004 18:54:37 +0100

In message <UgFoc.247831$rM4.10580678@news4.tin.it>, jFk_2
<spam_your_sister@aol.com> writes
>Hi guys,
>
>In the security log of my router I see many times:
>
>**ICMP Redirect from WAN** 80.28.250.121->>82.50.3.133, Type:5, Code:5
>(82.50.3.133 was my dinamic IP)
>
>I found info about codes 0 to 3 here
>http://www.iana.org/assignments/icmp-parameters but nothing about code 5.
>
>My router seems to go to "sleep mode" after few hours of work, nothig can
>pass through it and I must reset it (or to disable firewall) to make it
>work again.
>I can only ping but nothing else (no emule connection, no web, no mail, no
>news ...)
>
>May this attack (and this message) be the cause of my problem ?
>
>The router is a "GetNet Wireless AP Router", same as BR6104WB by Edimax.
>
>Thanks
>
>

According to "Internetworking with TCP/IP" Vol 1 by Douglas E Comer, for
the ICMP protocol, type field 5 means "redirect (change a route)", and
code value 5 means "source route failed".

Brian



Relevant Pages

  • Re: ICMP redirects are baad mkay?
    ... and not all found in RFC 1122. ... [>= Remember, an ICMP redirect cannot replace an ICMP redirect, so] ... [>that hits them back to the primary router. ...
    (comp.security.firewalls)
  • Re: Getting "ICMP Host redirect from gateway" response
    ... The ICMP Redirect message is generated to inform a local host that it ... should use a different next hop router for certain traffic. ... but send it to the default gateway and expect it to ...
    (comp.os.linux.networking)
  • Re: Watching for RWW breakins
    ... I'm doing everything I can find to protect it, including changing the Administrator account name, setting really obnoxious passwords, setting IP address filters in the router, and forwarding a nonstandard port to 443 for HTTPS access. ... Other discussions here have emphasized monitoring the security log, but what on earth do I watch for? ... If you have a firewall or router doing NAT, you can have the logs shipped to the server and then monitor the logs for connections that actually make it inbound. ...
    (microsoft.public.windows.server.sbs)
  • =?windows-1252?Q?Re=3A_monit_=96_can=27t_connect_from_browser?=
    ... This is a result of a IMCP redirect at the router ... Did you check that the port on the webserver handles ssl on port 2812, ... but I forgot that https would be on a *different* port! ...
    (comp.os.linux.networking)
  • =?windows-1252?Q?Re=3A_monit_=96_can=27t_connect_from_browser?=
    ... It seems that it does send a redirect, ... webserver directly with 192.168.2.2 (from inside my LAN). ... This is a result of a IMCP redirect at the router ... web-based administration tool ...
    (comp.os.linux.networking)