Advanced Ping: httping, dnsping, smtpping
blog.webernetz.net
blog.webernetz.net
#!/bin/bash
while sleep 0.5; do
nc -vv -w 1 -z ${1:-localhost} ${2:-22}
done $ alias sshammer
alias sshammer='ssh -o ConnectionAttempts\ 10000 -o ConnectTimeout\ 5' $ nmap -Pn -p domain e.gtld-servers.net
Starting Nmap 7.01 ( https://nmap.org ) at 2016-05-15 13:32 CDT
Nmap scan report for e.gtld-servers.net (192.12.94.30)
Host is up (0.072s latency).
PORT STATE SERVICE
53/tcp open domain
Nmap done: 1 IP address (1 host up) scanned in 0.22 seconds
The repeated ping function -- which is intended to display packet loss or delay -- isn't useful for TCP services.You can tunnel over DNS as well: https://zeltser.com/c2-dns-tunneling/
Just curious as to what problem you are solving by blocking ICMP.
It also often gets overlooked, so while "you can tunnel inside almost any protocol", it is very common for malware to use ICMP for C&C.
This isn't to say ICMP should be blocked completely. But limiting the size and the value of the payload in ICMP ECHO requests and replies can definitely help.
This is not true in the slightest.
And it'd only be realistic on windows as all other prevalent platforms require administrative privileges for such.
Lets be real here, ICMP is a particularly bad protocol for malware and that's why nobody uses it.
If yes, again assuming that all traffic is either monitored or blocked, have you done cost-benefit of monitoring ICMP for tunneled traffic vs blocking? A blocking rule need to be maintained, and it prevents diagnostics tools. If you have or will have a outside service that use heartbeat, such usage require whitelisting and maintenance for handling the permissions. In contrast, monitoring ICMP should just involve the same work as adding an additional protocol to the existing monitoring system.
One should also give some thought to the most common forms that adversaries use to tunnel traffic. TCP port 80 and 441 is a commonly used method to break through firewalls and nat, since those are considered outgoing ports which companies can't afford to block. (a small remark, where I work we do block those ports in some situations, and it has caught several intruders). Ports used for email is of course even more common to see malicious use from, and it is not uncommon that ISPs block all outgoing traffic on those ports. No one should consider blocking ICMP at all unless the more common traffic channels are monitored or blocked, unless they just want to create a false sense of security.
There are countless other situations where you want to receive an ICMP: e.g. "TTL expired" or "Fragmentation needed but DF bit set".