Snort mailing list archives
Re: ICMP type 8 code 80?
From: "Patterson, David R (IHS/HQ)" <david.patterson () ihs gov>
Date: Thu, 26 Jul 2012 15:52:29 +0000
I could be wrong but a type = 8 means an echo request, I believe that a code = 30 means Traceroute. David Patterson IHS IRT Team Lead Office of Information Technology (OIT) Division of Information Security (DIS) 505-248-4464 -----Original Message----- From: Castle, Shane [mailto:scastle () bouldercounty org] Sent: Thursday, July 26, 2012 8:44 AM To: snort-users () lists sourceforge net; emerging-sigs () emergingthreats net Subject: [Snort-users] ICMP type 8 code 80? I received a number of these early today: ------------------------------------------------------------------------ Count:1 Event#8.306289 2012-07-26 10:37:35 GPL ICMP undefined code 67.220.42.22 -> 192.168.13.92 IPVer=4 hlen=5 tos=0 dlen=60 ID=27393 flags=0 offset=0 ttl=13 chksum=1738 Protocol: 1 Type=8 Code=30 chksum=17093 ID=46085 seq=0 Payload: 83 C7 2E 00 EF BE AD DE EF BE AD DE EF BE AD DE ................ EF BE AD DE EF BE AD DE EF BE AD DE EF BE AD DE ................ Anybody have a clue what ICMP Type 8 Code 30 might mean? -- Shane Castle Data Security Mgr, Boulder County IT CISSP GSEC GCIH ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news! ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- ICMP type 8 code 80? Castle, Shane (Jul 26)
- Re: ICMP type 8 code 80? Ian Bowers (Jul 26)
- Re: ICMP type 8 code 80? Giles Coochey (Jul 26)
- Re: ICMP type 8 code 80? Giles Coochey (Jul 26)
- Re: ICMP type 8 code 80? Patterson, David R (IHS/HQ) (Jul 26)
- Re: ICMP type 8 code 80? Patterson, David R (IHS/HQ) (Jul 26)
- Re: [Snort-users] [Emerging-Sigs] ICMP type 8 code 80? Leonard P. Jacobs (Jul 28)
- Re: [Snort-users] [Emerging-Sigs] ICMP type 8 code 80? Leonard P. Jacobs (Jul 28)
- Re: [Emerging-Sigs] ICMP type 8 code 80? Rajiv D (Jul 28)