Snort mailing list archives

Re: ICMP PING CyberKit 2.2 Windows


From: "Jade E. Deane" <jade.deane () riven net>
Date: 19 Aug 2003 21:14:52 -0500

Anything you can do at your perimeter?  Sure, drop any ICMP echo
requests.  With that being said, my perimeter packet filter blocks type
8 messages, but of course the IDS sitting on a mirrored or otherwise
spanned switch port will see it regardless.

Regards,
Jade

On Tue, 2003-08-19 at 19:30, Stevo wrote:
Guys,

So what's the deal with the 72000 odd ICMP PING CyberKit 2.2 Windows alerts
I've got in the past few days??  It's frickin crazy...  I've read the posts
on here, but what is actually causing this and is there anything I can do at
my perimeter to stop these ICMP messages hitting my network??

It's just annoying and I don't want to remove the rule that picks up on the
ICMP PING CyberKit 2.2 Windows!!

Ideas??

Stevo




-------------------------------------------------------
This SF.net email is sponsored by Dice.com.
Did you know that Dice has over 25,000 tech jobs available today? From
careers in IT to Engineering to Tech Sales, Dice has tech jobs from the
best hiring companies. http://www.dice.com/index.epl?rel_code=104
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: