5 ms·
TLDR: A lot of companies block ICMP for security reasons. OP thinks you shouldn't and provides links explaining why. That said, if ICMP is still blocked, you mi
by dkopi 10y ago
TLDR: A lot of companies block ICMP for security reasons. OP thinks you shouldn't and provides links explaining why. That said, if ICMP is still blocked, you might be able to use httping, dnsping and smtpping as tools that provide similar information based on a server's responses to higher layered protocols.
- INTPenis 10y agoI'm not a network architect but I like it when ICMP is blocked because I know it can be used to tunnel traffic in penetration situations.
- dkopi 10y agoAny type of traffic can be used to tunnel other types of traffic. You can tunnel over DNS as well: https://zeltser.com/c2-dns-tunneling/ https://zeltser.com/c2-dns-tunneling/
- INTPenis 10y agoOf course but security is multi layered and blocking ICMP is one layer, while using internal DNS is another. It's mitigation that costs nothing.
- dkopi 10y agoICMP is a valuable diagnostics and control tool. Blocking it doesn't come without a cost.
- scurvy 10y agoWhat does blocking ICMP get you? (other than a broken network) Blocking ICMP fragments is fine if you are worried about DDoS attacks, but don't blanket block everything ICMP (especially ICMPv6). Just curious as to what problem you are solving by blocking ICMP.
- dkopi 10y agoICMP ECHO has an additional payload field thay we often ignore. Some malware is known to use the ICMP payload as a C&C channel, or to tunnel out stolen information: https://en.wikipedia.org/wiki/ICMP_tunnel https://en.wikipedia.org/wiki/ICMP_tunnel
- scurvy 10y agoYou can tunnel inside almost any protocol. That's not a great reason. Valid, sure; good, no.
- dkopi 10y agoWhile true - ICMP is a ubiquitous protocol used all over the internet, but computers and network devices a like. It also often gets overlooked, so while "you can tunnel inside almost any protocol", it is very common for malware to use ICMP for C&C. This isn't to say ICMP should be blocked completely. But limiting the size and the value of the payload in ICMP ECHO requests and replies can definitely help.
- ryanlol 10y ago> it is very common for malware to use ICMP for C&C. This is not true in the slightest. And it'd only be realistic on windows as all other prevalent platforms require administrative privileges for such.
- dkopi 10y agoGood thing malware doesn't have administrative privileges.
- ryanlol 10y agoUnless you're a member of ac1db1tch3z and happen to be sitting on a particularly big pile of local 0days, as a malware developer you wouldn't rely on having such privileges. Lets be real here, ICMP is a particularly bad protocol for malware and that's why nobody uses it.
- moonfern 10y agoWith iptables you can read packets, is it an icmp packet, what is it length and so on... If I was a hacker and I notice that icmp packets are blocked, I would feel less fear.
- kkirsche 10y agoI agree with this sentiment. To me, blocking ICMP solves a symptom of the security problem, not the actual problem
- belorn 10y agoEffective security know what assets they are defending, what threat exist, and what the cost benefit is of applying a defensive measure to prevent the threats. Assuming that you have identified some assets you want to protect, is the threat that someone might tunnel traffic outside of monitored channels? If yes, again assuming that all traffic is either monitored or blocked, have you done cost-benefit of monitoring ICMP for tunneled traffic vs blocking? A blocking rule need to be maintained, and it prevents diagnostics tools. If you have or will have a outside service that use heartbeat, such usage require whitelisting and maintenance for handling the permissions. In contrast, monitoring ICMP should just involve the same work as adding an additional protocol to the existing monitoring system. One should also give some thought to the most common forms that adversaries use to tunnel traffic. TCP port 80 and 441 is a commonly used method to break through firewalls and nat, since those are considered outgoing ports which companies can't afford to block. (a small remark, where I work we do block those ports in some situations, and it has caught several intruders). Ports used for email is of course even more common to see malicious use from, and it is not uncommon that ISPs block all outgoing traffic on those ports. No one should consider blocking ICMP at all unless the more common traffic channels are monitored or blocked, unless they just want to create a false sense of security.
- NetStrikeForce 10y agoThis is often said by people that do not understand that ICMP is not only echo/reply. There are countless other situations where you want to receive an ICMP: e.g. "TTL expired" or "Fragmentation needed but DF bit set".
- 13of40 10y agoI wrote a tool a long time back for testing PowerShell remoting connections that started with name resolution, then tried ICMP, TCP, HTTP, WinRM, etc. to figure out what layer was failing. Ping was critical to start out with because if it worked but IP-based protocols failed it was nearly always an IPSec problem. If ping didn't work, it was the firewall.
- markbnj 10y agoI just reach for curl in situations where I need a layer 7 request/response to see if things are up. I can see where this might be a little easier, especially for repeated requests.