4 ms·
ICMP ECHO has an additional payload field thay we often ignore. Some malware is known to use the ICMP payload as a C&C channel, or to tunnel out stolen informat
by dkopi 10y ago
ICMP ECHO has an additional payload field thay we often ignore.
Some malware is known to use the ICMP payload as a C&C channel, or to tunnel out stolen information:
https://en.wikipedia.org/wiki/ICMP_tunnel https://en.wikipedia.org/wiki/ICMP_tunnel
- scurvy 10y agoYou can tunnel inside almost any protocol. That's not a great reason. Valid, sure; good, no.
- dkopi 10y agoWhile true - ICMP is a ubiquitous protocol used all over the internet, but computers and network devices a like. It also often gets overlooked, so while "you can tunnel inside almost any protocol", it is very common for malware to use ICMP for C&C. This isn't to say ICMP should be blocked completely. But limiting the size and the value of the payload in ICMP ECHO requests and replies can definitely help.
- ryanlol 10y ago> it is very common for malware to use ICMP for C&C. This is not true in the slightest. And it'd only be realistic on windows as all other prevalent platforms require administrative privileges for such.
- dkopi 10y agoGood thing malware doesn't have administrative privileges.
- ryanlol 10y agoUnless you're a member of ac1db1tch3z and happen to be sitting on a particularly big pile of local 0days, as a malware developer you wouldn't rely on having such privileges. Lets be real here, ICMP is a particularly bad protocol for malware and that's why nobody uses it.