Snort mailing list archives
Re: ICMP type 8 code 80?
From: Ian Bowers <iggdawg () gmail com>
Date: Thu, 26 Jul 2012 11:00:01 -0400
Looks like a breadcrumb or phone-home packet. non-existant type/code combo and repeating payload. both very easy to spot in a network stream if you know what you're looking for. not sure why it would get sent out to you though, unless you're on a dynamic address and it was meant for the previous occupant of the address. Another possibility is a researcher sending out an intentionally broken packet to see how different hosts respond. -Ian On Thu, Jul 26, 2012 at 10:43 AM, Castle, Shane <scastle () bouldercounty org>wrote:
I received a number of these early today: ------------------------------------------------------------------------ Count:1 Event#8.306289 2012-07-26 10:37:35 GPL ICMP undefined code 67.220.42.22 -> 192.168.13.92 IPVer=4 hlen=5 tos=0 dlen=60 ID=27393 flags=0 offset=0 ttl=13 chksum=1738 Protocol: 1 Type=8 Code=30 chksum=17093 ID=46085 seq=0 Payload: 83 C7 2E 00 EF BE AD DE EF BE AD DE EF BE AD DE ................ EF BE AD DE EF BE AD DE EF BE AD DE EF BE AD DE ................ Anybody have a clue what ICMP Type 8 Code 30 might mean? -- Shane Castle Data Security Mgr, Boulder County IT CISSP GSEC GCIH ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- ICMP type 8 code 80? Castle, Shane (Jul 26)
- Re: ICMP type 8 code 80? Ian Bowers (Jul 26)
- Re: ICMP type 8 code 80? Giles Coochey (Jul 26)
- Re: ICMP type 8 code 80? Giles Coochey (Jul 26)
- Re: ICMP type 8 code 80? Patterson, David R (IHS/HQ) (Jul 26)
- Re: ICMP type 8 code 80? Patterson, David R (IHS/HQ) (Jul 26)
- Re: [Snort-users] [Emerging-Sigs] ICMP type 8 code 80? Leonard P. Jacobs (Jul 28)
- Re: [Snort-users] [Emerging-Sigs] ICMP type 8 code 80? Leonard P. Jacobs (Jul 28)
- Re: [Emerging-Sigs] ICMP type 8 code 80? Rajiv D (Jul 28)