The following are ICMP Query Message
signatures:
- 2000—Echo Reply (severity 1,
information): This signature is triggered when an IP datagram is
received with the "protocol" field of the IP header set
to 1 (ICMP) and the "type" field in the ICMP header set
to 0 (Echo Reply). ICMP Echo Replies have been used to bypass
packet filter security policies as they are rarely filtered in
either incoming or outgoing traffic. May be used to establish a
communication channel or to perform DoS attacks.
- 2004—Echo Request (severity 1,
information): This signature is triggered when an IP datagram is
received with the "protocol" field of the IP header set
to 1 (ICMP) and the "type" field in the ICMP header set
to 8 (Echo Request). ICMP Echo Requests are commonly used to
perform reconnaissance sweeps of networks. These sweeps often are
a prelude to attack. Additionally they may be used to perform DoS
attacks.
- 2007—Timestamp Request (severity
1, reconnaissance/information): This signature is triggered when
an IP datagram is received with the "protocol" field of
the IP header set to 1 (ICMP) and the "type" field in
the ICMP header set to 13 (Timestamp Request). ICMP Timestamp
Requests could be used to perform reconnaissance sweeps of
networks. These sweeps often are a prelude to attack. Additionally
they may be used to perform DoS attacks. No known exploits
incorporate this option. This does not preclude the possibility
that exploits do exist outside of the realm of Cisco Systems'
knowledge domain.
- 2008—Timestamp Reply (severity 1,
information): This signature is triggered when an IP datagram is
received with the "protocol" field of the IP header set
to 1 (ICMP) and the "type" field in the ICMP header set
to 14 (Timestamp Reply). ICMP Timestamp Replies could be used to
perform DoS attacks. No known exploits incorporate this option.
This does not preclude the possibility that exploits do exist
outside of the realm of Cisco Systems' knowledge domain.
- 2009—Information Request (severity
1, information): This signature is triggered when an IP datagram
is received with the "protocol" field of the IP header
set to 1 (ICMP) and the "type" field in the ICMP header
set to 15 (Information Request). This signature is included for
completeness. No known exploit exists. This does not preclude the
possibility that exploits do exist outside of the realm of Cisco
Systems' knowledge domain.
- 2010—Information Reply (severity
1, information): This signature is triggered when an IP datagram
is received with the "protocol" field of the IP header
set to 1 (ICMP) and the "type" field in the ICMP header
set to 16 (ICMP Information Reply). This signature is included for
completeness. No known exploit exists. This does not preclude the
possibility that exploits do exist outside of the realm of Cisco
Systems' knowledge domain.
- 2011—Address Mask Request (severity
1, reconnaissance/information): This signature is triggered when
an IP datagram is received with the "protocol" field of
the IP header set to 1 (ICMP) and the "type" field in
the ICMP header set to 17 (Address Mask Request). ICMP Address
Mask Requests could be used to perform reconnaissance sweeps of
networks. These sweeps often are a prelude to attack. Additionally
they may be used to perform DoS attacks. No known exploits
incorporate this option. This does not preclude the possibility
that exploits do exist outside of the realm of Cisco Systems'
knowledge domain.
- 2012—Address Mask Reply (severity
1, information): This signature is triggered when an IP datagram
is received with the "protocol" field of the IP header
set to 1 (ICMP) and the "type" field in the ICMP header
set to 18 (Address Mask Reply). ICMP Timestamp Replies could be
used to perform DoS attacks. No known exploits incorporate this
option. This does not preclude the possibility that exploits do
exist outside of the realm of Cisco Systems' knowledge domain.
|
|