4 ms·
ping and traceroute used to be very useful tools. Then for a period of time -- maybe still ongoing -- sysadmins and some network security folks decided that by
by psim1 4y ago
ping and traceroute used to be very useful tools. Then for a period of time -- maybe still ongoing -- sysadmins and some network security folks decided that by blocking ALL ICMP at their network edge, they were increasing security. (Wrong!) As a result, you get hanging traceroutes with one or two hops left and you can't use ping to verify a host is online. Worse, blocking all ICMP breaks things like MTU discovery along the path. Recently I have seen admins coming to their senses and unblocking ICMP, but it's still an old rule-of-thumb held by many.
- JackGreyhat 4y agoI still keep it blocked for his reason: https://socfortress.medium.com/data-exfiltration-using-icmp-and-how-to-detect-it-69a799cca234 https://socfortress.medium.com/data-exfiltration-using-icmp-...