Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] About the ICMP reply |
|---|---|
| Date: | Mon, 07 Jan 2008 14:08:55 +0800 |
Hi all,
I'm confused by the reply in class of ICMP.
For example, 'ICMP Timestamp Request' are from external to home, but the 'ICMP Timestamp Reply' is still from external to home, then how can we detect the reply from the home server?
Furthermore, 'ICMP Address Mask Reply' are from home to external, but 'ICMP Address Mask Reply undefined code' are from external to home, while these too alert are only different at the 'undefined code'.
Consider the task of the snort is to protect the user in home net, I think the request should be external to home, while the reply should be home to external. If the external server is also concerned, it should be another set of alerts to describe the attack.
Can any body tell me whether my above oponion is correct or not?
Best regards
Mingming
------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] About the connection in the alert of BackDoor, Sun |
|---|---|
| Next by Date: | Re: [Snort-sigs] About the connection in the alert of BackDoor, Joel Esler |
| Previous by Thread: | [Snort-sigs] About the ICMP reply, Sun |
| Next by Thread: | Re: [Snort-sigs] About the ICMP reply, trains |
| Indexes: | [Date] [Thread] [Top] [All Lists] |