[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <712d8d5668e9c41160ae3fe7896cc25e@teknovis.com>
From: andfarm at teknovis.com (Andrew Farmer)
Subject: ICMP Covert channels question
On 28 Jan 2005, at 14:45, cyberpixl wrote:
<snip>
> Assume there is a local machine (our target) with ip 192.168.0.2 that
> is connected to the internet using a router 192.168.0.1/88.88.88.88
> (that is not blocking icmp packets) and my machine is say,
> 33.33.33.33. If i then send an icmp packet to the 88.88.88.88 router
> with source ip set to 192.168.0.2, would it forward that packet to the
> host in its local network, or will it discard it?
Depends entirely on the router's configuration. Most will forward it;
however, some will, whether out of misimplementation or paranoia,
drop it.
> Is there any way to deliver my packet to that local machine?
There are some other nifty tricks you ought to check out. For example,
take a look at LimeWire's 'UDPConnect' protocol.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: PGP.sig
Type: application/pgp-signature
Size: 186 bytes
Desc: This is a digitally signed message part
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20050128/d85b642d/PGP.bin
Powered by blists - more mailing lists