Re: Blocked incoming ICMP, getting outgoing ICMP [3] Destination Unreachable



Dom <invalid@xxxxxxxxxxxxxxx> wrote:
How 'bout clearing up this distinction between real and imitation
traceroute.

The original is from Van Jacobson, 4.3BSD.

It sends UDP packets with a very small TTL and waits until the ICMP
TIME_EXCEEDED answer arrives from each gateway along the route to a
host.

Microsoft's traceroute. Do they both not accomplish the same thing? I
would argue that ICMP echo is the proper protocol for a traceroute
because a firewalled target host is most likely to reply to an echo
request.

I'd like to see that you're right. But ICMP echo filtering is a
widespread disease in the days of "Personal Firewalls" and "stealthing".

I would place hping above all other traceroute utilities. Hping
can perform traceroutes with many protocols and ports.

With hping, you can do completely other things than a traceroute, too.
It's a packet generator, not a traceroute utility.

Yours,
VB.
--
Wenn Du "Ich sehe die Mathematik als einzigen Bereich an, wo es klare
Beweise gibt." und "Ich fuehle mich in einem Anzug unwohl." als Aussagen
mit aequivalentem Meinungsinhalt betrachtest, hast Du mit Deinem Gleichnis
recht. (Michail Bachmann zu Thomas Wallutis in d.a.s.r)
.



Relevant Pages

  • Re: Blocked incoming ICMP, getting outgoing ICMP [3] Destination Unreachable
    ... The real LBL traceroute ... icmp error in reponse to an icmp packet. ... icmp time exceeded in response to an icmp echo or echo reply. ... had created a b0rken network stack that could be kicked over by sending ...
    (comp.security.firewalls)
  • RE: traceroute-like tool for UDP or TCP packet
    ... >> Linux uses UDP packets to traceroute, ... an ICMP packet is a type of UDP packet. ...
    (Security-Basics)
  • Re: icmp type 11 not go via nat POSTROUTING table
    ... everthing is working as it "should", there is no reason for a "ICMP ... I generated two test icmp packets ... This is how traceroute knows the IP of the ... If x.y.z.t is a private IP address, it cannot be tracerouted anyway, so ...
    (comp.os.linux.networking)
  • Re: Traceroute anomaly
    ... Hm - checking back on previous exchanges I have had over traceroute I ... I'm sorry I "muddied the water" with RFC 1393 and the IP "route ... Do remember that I said I used to teach ICMP and what seems to have ... generated when the packet which might give rise to the ICMP packet is ...
    (comp.dcom.sys.cisco)
  • Re: allowing icmp still doesnt allow traceroute
    ... >> 00600 allow icmp from any to any ... >> for ipfw, and i still get sendto Permission denied when ... >> I try to traceroute. ... You want to allow UDP packets in that above range ...
    (FreeBSD-Security)