Security Incidents mailing list archives

Re: Odd windows ICMP... any ideas what this is?


From: "Raistlin" <raistlin () s0ftpj org>
Date: Fri, 13 Jun 2003 23:28:14 +0200

Although it may not be directly related, wasn't there some chat
server written some time ago that distributed its text through icmp?

It seems unrelated, but there's plenty of tools using ICMP to carry data out
there. An example is
our own ICMP tunnelling library and covert shell
(http://www.s0ftpj.org/tools/007shell.tgz), also ported to windows
(http://www.s0ftpj.org/tools/icmp_tunnel.h)

Raistlin

S0ftPj - Digital Security for Y2K

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/E/IT/TW d++(-) s++:-- a--  C++++ U++++ P(---) L+++ E---- 
W+++ N++ o K+ w--- O- M-- V-- PS++ PE- Y++ PGP++ t+++ 5+
X+@ R+++ tv-- b+++ DI++++ D++ G+ e+++>++++(*) h! r% y+
------END GEEK CODE BLOCK------



----------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
world's premier technical IT security event! 10 tracks, 15 training sessions, 
1,800 delegates from 30 nations including all of the top experts, from CSO's to 
"underground" security specialists.  See for yourself what the buzz is about!  
Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
----------------------------------------------------------------------------


Current thread: