3 ms·
I agree that some captive portals/firewalls do block ICMP but still I've seen many in my country which don't.
by vampire_dk 11y ago
I agree that some captive portals/firewalls do block ICMP but still I've seen many in my country which don't.
- dogma1138 11y agoWell the question is then what's the point other than a personal exercise? There is plenty of ICMP / multi protocol tunnels software out there for both linux and windows much of it doesn't require administrative privileges. Also ptunnel comes standard with some linux distro's these days Ubuntu and so do probably most of it's derivatives, and as far as raw performance goes ptunnel is also the highest performing one capable of achieving about 150kbps which isn't that bad considering the sheer amount of packets and overhead you get. http://manpages.ubuntu.com/manpages/gutsy/man8/ptunnel.8.html http://manpages.ubuntu.com/manpages/gutsy/man8/ptunnel.8.htm...
- vampire_dk 11y agoI tried using some but couldn't get them to work. Probably because many were developed long time back. There have been many recent changes in the kernel.
- simoncion 11y ago> Well the question is then what's the point other than a personal exercise? What's your question? Is it "What's the point of blocking ICMP?"? Or is it the opposite question? If it's the former, then there are sysadmins out there who cargo-cult their network configuration and listen to folks like Gibson Research Corporation who've been giving really bad advice [0] for the past decade+. [0] Specifically, they strongly recommend dropping all traffic to ports that don't have listening services, along with all ICMP, rather than rejecting said traffic and allowing all non-problematic ICMP. They also have a "handy" tool [1] to make it look like doing anything else is "DANGEROUS": (The tool reports [2] if your site responds to ICMP echo requests.) [1] https://www.grc.com/shieldsup https://www.grc.com/shieldsup [2] Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.
- PinguTS 11y agoAny major captive portal re-routes DNS requests to their Login-IP and block any IP leaving the local network. That essentily prohibits any ICMP request to the outside world.
- gonzo 11y agoSure, but they still need to lookup the name.
- johnsmithhenry 11y agoExactly. I've seen many captive portals that don't block ICMP.