Project

General

Profile

Actions

Feature #1566

open

ICMPv4 control channel detection

Added by Vlad Solontsov about 7 years ago. Updated almost 3 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

I'm trying to find a way detecting control channels over ICMP (ICMP shell and others).
As a proposal I would like to detect:
  • Unsolicited ECHO Reply
  • ECHO Reply with different payload

If there is no such options (I'm pretty sure in it) I will be happy to try and contribute.
In this case I'd like someone experienced to validate the idea details.

Actions

Also available in: Atom PDF