Security Incidents mailing list archives
More fun stuff from demon internet (ICMP/120 ?)
From: epadin () WAGWEB COM (Ed Padin)
Date: Tue, 9 May 2000 15:02:16 -0400
I just saw the following hit my firewall: DATE: May,9,13:54:29 DIRECTION: fw-in ACTION: deny INTERFACE: eth1 DESCRIPTION: Internet PROTOCOL: icmp/120 SOURCE IP: 195.11.172.80 DESTINATION IP: 216.89.84.21 SOURCE PORT: N/A DESTINATION PORT: N/A LENGTH: 84 TYPE: 0x00 ID: 40927 TTL: 0x0000 OPT: 246 icmp/120? I'm pretty sure that ICMP types greater than 37 are reserved. Anybody got any ideas what this may be? I wish I had grabbed the packet data.
Current thread:
- More fun stuff from demon internet (ICMP/120 ?) Ed Padin (May 09)
- source port zero scans against DNS servers dorqus (May 12)
- Re: More fun stuff from demon internet (ICMP/120 ?) thomas lakofski (May 12)