9 ms·
IP traffic over ICMP tunneling
- raven_stark 11y agoNow that's pretty amazing!
- PinguTS 11y agoNot the first of its kind, just look-up in Wikipedia: https://en.wikipedia.org/wiki/ICMP_tunnel https://en.wikipedia.org/wiki/ICMP_tunnel Any captive portal these days block also ICMP. Most firewalls block ICMP these days, because the days of blacklisting are over and ICMP is not the one who is getting white listed. Why? The only way these days is to misuse DNS. But even that works less and less reliable.
- vampire_dk 11y agoI agree that some captive portals/firewalls do block ICMP but still I've seen many in my country which don't.
- dogma1138 11y agoWell the question is then what's the point other than a personal exercise? There is plenty of ICMP / multi protocol tunnels software out there for both linux and windows much of it doesn't require administrative privileges. Also ptunnel comes standard with some linux distro's these days Ubuntu and so do probably most of it's derivatives, and as far as raw performance goes ptunnel is also the highest performing one capable of achieving about 150kbps which isn't that bad considering the sheer amount of packets and overhead you get. http://manpages.ubuntu.com/manpages/gutsy/man8/ptunnel.8.html http://manpages.ubuntu.com/manpages/gutsy/man8/ptunnel.8.htm...
- vampire_dk 11y agoI tried using some but couldn't get them to work. Probably because many were developed long time back. There have been many recent changes in the kernel.
- simoncion 11y ago> Well the question is then what's the point other than a personal exercise? What's your question? Is it "What's the point of blocking ICMP?"? Or is it the opposite question? If it's the former, then there are sysadmins out there who cargo-cult their network configuration and listen to folks like Gibson Research Corporation who've been giving really bad advice [0] for the past decade+. [0] Specifically, they strongly recommend dropping all traffic to ports that don't have listening services, along with all ICMP, rather than rejecting said traffic and allowing all non-problematic ICMP. They also have a "handy" tool [1] to make it look like doing anything else is "DANGEROUS": (The tool reports [2] if your site responds to ICMP echo requests.) [1] https://www.grc.com/shieldsup https://www.grc.com/shieldsup [2] Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.
- PinguTS 11y agoAny major captive portal re-routes DNS requests to their Login-IP and block any IP leaving the local network. That essentily prohibits any ICMP request to the outside world.
- gonzo 11y agoSure, but they still need to lookup the name.
- johnsmithhenry 11y agoExactly. I've seen many captive portals that don't block ICMP.
- scurvy 11y agoWhy would you block ICMP rather than police it or only allow certain opcodes and sizes? I hope the people blocking ICMP don't ever try and run IPv6.
- cortesoft 11y agoOf course they aren't going to try IPv6. Not because of ICMP, but they won't try it.
- exelius 11y agoYeah, that was my thought. Does everyone really think that the companies building these security platforms haven't thought of this? It's not an obscure protocol or anything, and ICMP has plenty of other potential abuses that would lead network admins to block it.
- est 11y ago> The only way these days is to misuse DNS How about IP over TCP SYN.
- matiasb 11y agoHans is a nice one too: http://code.gerade.org/hans/ http://code.gerade.org/hans/
- redwards510 11y agoThe documentation for this is superb! I know what it does, why I'd want to use it, how to use it, where to use it and what it looks like in wireshark. Well done!
- vampire_dk 11y agoThanks for the feedback :)
- de_wq912AesppE5 11y agoThere are DNS tunneling apps which will (usually) get past those captive portals that block ICMP. It's just slower.
- vampire_dk 11y agoI have tested it. Internet speed difference is negligible. Yup DNS tunneling apps can also be used.
- txutxu 11y agoI use to restrict ICMP to echo/reply using -m icmp on iptables, but this uses just that kind of packets... Is there anyway to stop things like this at the corporate firewall?
- vampire_dk 11y agoYes. In my opinion they should restrict the payload size of an ICMP message. Blocking all echo/reply can have adverse impact on other applications as well.
- jacquesm 11y agoA couple of million small packets in a short timeframe will still eat up your resources. If an application needs ICMP echo to pass transparently through your firewall then you should probably review your need for that application, you're one step away from becoming a partner in someone else's amplification attack.
- toast0 11y agoICMP echo isn't amplification, as long as you don't respond to multicast/broadcast addresses. It's still 1:1 reflection, so you probably want to rate limit if it's simple (FreeBSD and Linux come out of the box with sane default rate limits).
- jacquesm 11y agoIt is amplification if you allow the packets through transparently because all the hosts behind your firewall will respond if you send an echo request to the broadcast address. So you're going to have to do a little bit more configuration than just allow a maximum packet size if you're going to allow ICMP to transit at all you should also limit the allowed set of addresses (you should do that regardless, but echo can be used for amplification requests by virtue of the broadcast feature of the IP protocol). Hence the 'one step away'. This was known as the 'smurf' attack. Fortunately this is now mostly a thing of the past. But poking holes in your firewall for ICMP is a delicate affair.
- victorhooi 11y agoFor anybody that's tried both - how do these compare to DNS tunnels (e.g. iodine), in terms of speed and reliability?
- vampire_dk 11y agoI haven't tried comparing both. I don't have much resources. All I can say is that using icmptunnel, one couldn't differentiate whether it's using tunnel or direct internet. Hence ICMP tunneling was very fast. Although I'm interested in comparison as well :)
- dogma1138 11y agoDNS is less reliable, but could give you bigger throughput (you can send and request large records) ICMP packets would arrive quicker, will be more reliable will bypass various DNS hijackers (common with many ISP's) along the way. DNS also requires you to have a DNS server and a domain, and you'll need something to constantly clear the cache on the local machine otherwise you'll eventually run out of room even if you are going to use the max available DNS record size. If anything in the way will keep your DNS queries in cache then you might be screwed and run out of space very quickly. If you need internet access ICMP tunnel will be better, bandwidth will be limited but it will be more or less a P2P tunnel, if you need to exfiltrate data without explicitly needing to maintain a bi-directional tunnel DNS is the way to go, will also work in more captive portal restrictive cases than ICMP. Today ICMP is usually utterly blocked DNS sometimes work especially in common cases where the restricted network offers some white listed sites (e.g. airport wifi that allows you to access the airport's site and the local train service but blocks everything else).
- vampire_dk 11y agoWith even ICMP you can send/receive large messages. There is no restriction on the maximum payload length.
- dogma1138 11y agoI haven't seen a single network stack that doesn't limit the size of the tailing payload or packet in general (MTU's ;)), go try and push 65507 bytes of payload into the message and tell me how it goes. In any case DNS tunnel offers you both TCP and UDP tunneling at much higher throughput, I'll take a look at your code when I'll have the time and see how it compares to ptunnel or ICMP shell.
- piyush8311 11y agoI just tried iodine and icmptunnel. Can't say for sure but I think icmptunnel was faster. At least for my internet
- vampire_dk 11y agoThat's good news for me. :)
- p4bl0 11y agoThat is what I would expect to happen. The problem is that most captive portals still let DNS through but not ICMP. Having said that, I'm sure there are other usage for such a tool :).
- _aryan_ 11y agoI ahve also tried it. It's working quite smoothly, performance is pretty good!
- xbeta 11y agoAnyone test this against China GFW and get it working?
- legulere 11y agoNormal tunnels also work around the GFW, so there's no reason to do ICMP tunneling.
- thaumasiotes 11y agoThe GFW attacks most normal tunnels, causing unreliable performance.
- NetStrikeForce 11y agoSoftEther, a multi platform and open-source software supports ICMP and DNS tunnelling among other things (SSL, OpenVPN, IPsec, etc) http://www.softether.org http://www.softether.org
- redwards510 11y agoAfter reading the product page, this product seems too good to be true (OSS, supports every OS and every type of VPN). Is there some kind of catch? How come I've never heard of it until now?
- hueving 11y agoIt's written in C++. /s I suspect it hasn't gotten a lot of widespread publication in English forums because it's from a University project from Japan so there aren't a lot of English-speaking contributors (there are only 9 contributors to the official repo). Additionally, it was only open sourced in 2014 so as an open source project it's pretty young.
- tw04 11y agoI know among the pfsense group originally there was skepticism that it wasn't back doored by a government agency (not because there was proof), because of the fact it had such a great feature set while being so new a project. Now that it's open sourced, I'm interested to see if people pick it up. It definitely looks legit.
- xpinguin 11y agoI remember postponing my payments to the ISP, which hadn't blocked ICMP for anybody, by using ptunnel: http://www.cs.uit.no/~daniels/PingTunnel/ http://www.cs.uit.no/~daniels/PingTunnel/ It was pretty much usable circa 2008... btw, in debian (and probably, derivatives), it is just apt-get away from being installed.
- deleted 11y ago[deleted]
- callumlocke 11y agoCan someone explain to a non-network person the significance of being able to tunnel IP traffic over ICMP?
- thebakeshow 11y agoYou can potentially bypass firewalls and prevent inspection of your traffic depending on how the network is configured
- vesinisa 11y agoA few years back, I was assigned to work at a BigCorp's premises. They had really tight network security: all outward connections were blocked except through a dedicated HTTP proxy. This was bad news, since stuff like SSH are absolutely essential in my job. After few days of mobile tethering, I realized I could ask their HTTP proxy to open an HTTPS connection to a server outside the network, but instead of sending HTTPS traffic through the proxy, I could send any traffic - like SSH. With this, I was ultimately able to open an SSH-tunnel to my own shell server running OpenVPN outside their network, which then allowed a (surprisingly stable and fast) access to the internet at wide – via an OpenVPN-tunnel wrapped in an SSH-tunnel pretending to be an HTTPS-tunnel. I don't recall whether ICMP was allowed out at the BigCorp., but I am pretty sure someone will one day find a tool like this quite useful in a similar situation.. :)
- Laforet 11y agoSounds like they enabled HTTP CONNECT without limiting the accepted port range, so any protocol will go through. Maybe this is why Microsoft Azure never allowed ICMP travseral through their outer firewall despite frequent request from users....
- motoboi 11y agoIt's common to run OpenVPN on TCP port 443 (HTTPS) to avoid such restrictions. The Great China Firewall and others need deep packet inspection, heuristics and AI to find tunnels set up that way.
- andrewchambers 11y agoBlocking based on port is a silly thing. He probably just ran ssh on port 443 to get around it.
- Laforet 11y agoThat's another possibility, the comment above can be interpreted either way. In any case they were probably running something like squid with very basic level 7 filtering, so if something comes on 443 they have no option but to forward it.
- Sami_Lehtinen 11y agoSome of the very early IP telephony apps (20 yrs ago) used the very same trick.
- fl0m 11y agoUsing ICMP reply only in both side is more convinient than ICMP reques/reply. In this case you do not need to write this, for example echo 1 | dd of=/proc/sys/net/ipv4/icmp_echo_ignore_all