Snort mailing list archives

RE: ISD171/ping zeros - One legit use


From: "Ofir Arkin" <ofir () sys-security com>
Date: Fri, 1 Jun 2001 01:46:05 -0700

Rich,

This is an issue dealt in this mailing lists again and again :)

You might wish to search the archives and find out that HPUX 11.x, 10.30,
AIX 4.3.x has a 'unique' PMTU discovery process using ICMP Echo requests
that produce the same patterns you described.

You can also read the appropriate section in my paper ICMP Usage in Scanning
available from http://www.sys-security.com.


Ofir Arkin [ofir () sys-security com]
Founder
The Sys-Security Group
http://www.sys-security.com
PGP CC2C BE53 12C6 C9F2 87B1 B8C6 0DFA CF2D D360 43FA


-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net]On Behalf Of Rich Adamson
Sent: Thursday, May 31, 2001 2:05 PM
To: Snort Users Postings
Subject: [Snort-users] ISD171/ping zeros - One legit use


FYI...

One of our sites has been observing:
  09:49:15 snort[2907]: IDS171/ping zeros: x.x.x.x -> y.y.y.y
from snort. The content of these ping packets is essentially 1500 bytes
of zeros (0's), and were arriving from five IP addresses assigned around
the world.

In researching the "source" of these packets, we received the following
response from this well-known international company:

"What you are seeing is a Wide area load balancing system trying to figure
out which of our 3 data centers is closest to you.  Someone on your network
requested one of our websites, and our DNS/load balancing system tries
probing your nameserver that the initial dns request came from, and
instructs the other data centers to do the same to collect path metrics.
Subsequent requests from your network result in being handed an IP for the
closest/fastest data center.  http://www.f5.com has the relavent information
on how the system works.

If you'd like to be put in an exclude list, we can stop the probes to your
network.  It tries to be as quiet as possible, but is in no way malicious.
It does tend to set off some IDS systems though."

A search of multiple sites including snort.org and whitehats.org did not
find any "negative" comments relative to IDS171, only one "could be an
issue".

Rich



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: