6 ms·
Any type of traffic can be used to tunnel other types of traffic. You can tunnel over DNS as well: https://zeltser.com/c2-dns-tunneling/ https://zeltser.com/c2
by dkopi 10y ago
Any type of traffic can be used to tunnel other types of traffic.
You can tunnel over DNS as well:
https://zeltser.com/c2-dns-tunneling/ https://zeltser.com/c2-dns-tunneling/
- INTPenis 10y agoOf course but security is multi layered and blocking ICMP is one layer, while using internal DNS is another. It's mitigation that costs nothing.
- dkopi 10y agoICMP is a valuable diagnostics and control tool. Blocking it doesn't come without a cost.
- scurvy 10y agoWhat does blocking ICMP get you? (other than a broken network) Blocking ICMP fragments is fine if you are worried about DDoS attacks, but don't blanket block everything ICMP (especially ICMPv6). Just curious as to what problem you are solving by blocking ICMP.
- dkopi 10y agoICMP ECHO has an additional payload field thay we often ignore. Some malware is known to use the ICMP payload as a C&C channel, or to tunnel out stolen information: https://en.wikipedia.org/wiki/ICMP_tunnel https://en.wikipedia.org/wiki/ICMP_tunnel
- scurvy 10y agoYou can tunnel inside almost any protocol. That's not a great reason. Valid, sure; good, no.
- dkopi 10y agoWhile true - ICMP is a ubiquitous protocol used all over the internet, but computers and network devices a like. It also often gets overlooked, so while "you can tunnel inside almost any protocol", it is very common for malware to use ICMP for C&C. This isn't to say ICMP should be blocked completely. But limiting the size and the value of the payload in ICMP ECHO requests and replies can definitely help.
- ryanlol 10y ago> it is very common for malware to use ICMP for C&C. This is not true in the slightest. And it'd only be realistic on windows as all other prevalent platforms require administrative privileges for such.
- dkopi 10y agoGood thing malware doesn't have administrative privileges.
- ryanlol 10y agoUnless you're a member of ac1db1tch3z and happen to be sitting on a particularly big pile of local 0days, as a malware developer you wouldn't rely on having such privileges. Lets be real here, ICMP is a particularly bad protocol for malware and that's why nobody uses it.