Re: Blocked incoming ICMP, getting outgoing ICMP [3] Destination Unreachable
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Blocked incoming ICMP, getting outgoing ICMP [3] Destination Unreachable

From: Volker Birk <bumens@dingens.org>
Date: Sun Feb 26 2006 - 08:48:08 CET

Dom <invalid@invalid.invalid> wrote:
> How 'bout clearing up this distinction between real and imitation
> traceroute.

The original is from Van Jacobson, 4.3BSD.

It sends UDP packets with a very small TTL and waits until the ICMP
TIME_EXCEEDED answer arrives from each gateway along the route to a
host.

> Microsoft's traceroute. Do they both not accomplish the same thing? I
> would argue that ICMP echo is the proper protocol for a traceroute
> because a firewalled target host is most likely to reply to an echo
> request.

I'd like to see that you're right. But ICMP echo filtering is a
widespread disease in the days of "Personal Firewalls" and "stealthing".

> I would place hping above all other traceroute utilities. Hping
> can perform traceroutes with many protocols and ports.

With hping, you can do completely other things than a traceroute, too.
It's a packet generator, not a traceroute utility.

Yours,
VB.

-- 
Wenn Du "Ich sehe die Mathematik als einzigen Bereich an, wo es klare
Beweise gibt." und "Ich fuehle mich in einem Anzug unwohl." als Aussagen
mit aequivalentem Meinungsinhalt betrachtest, hast Du mit Deinem Gleichnis
recht. (Michail Bachmann zu Thomas Wallutis in d.a.s.r)
Received on Mon May 1 00:53:07 2006