alert icmp $EXTERNAL_NET any -> $HOME_NET any \
(msg:"ICMP PING BeOS4.x"; \
content:"|00000000000000000000000008090a0b|"; itype:8;depth:32; \
reference:arachnids,151; sid:370; classtype:misc-activity; rev:4;)


This event indicates an icmp echo request originating from the common
utility known as 'ping'.

This event in nature is in its natural state is used to measure the health
and or availability of an ip protocol on a network connected device
through the use of an icmp echo request.

The perverse use of the icmp echo request could indicate an attacker
trying to map your network by seeing what hosts respond and what type of
response is generated from these hosts to perform remote operating system

This particular event indicates the icmp echo request appears to be
originating from a BeOS4(ish) operating system.


In a natural state the impact of this event indicates an attempt to
request the availability of a host, while in a paranoid mindset this could
be viewed as a precursor to an upcoming attack.

Detailed Information:

The information we are looking for in this icmp echo request
 "|00000000000000000000000008090a0b|" with the maximum depth of 32 bytes
in the icmp payload.

Affected Systems:
any system with a ip stack.

Attack Scenarios:

Normal use:
ping remote.host.ip
Hostile use:
could be used by tools like nemesis,hping2,or nmap

Ease of Attack:

False Positives:

False Negatives:

Corrective Action:

Additional References:
http://www.whitehats.com arachnids 151

