[Snort-users] icmp

Guillaume guillaume at ...4029...
Thu Nov 15 00:21:02 EST 2001


En réponse à Ryan Russell <ryan at ...35...>:

> On Wed, 14 Nov 2001, Peter VE wrote:
> 
> > All I wanted to achieve is to fool the remote users, letting them
> believe my host is unreachable for icmp traffic...
> 
> Normal behavior for ICMP to a host that doesn't allow it is no
> response.


Well... Let's say it is a normal behavio(u)r for a firewall admin to disable
ICMP responses !!
The normal behavio(u)r of a host that does not allow ICMP messages is to send a
"destination host administratively prohibited" or something like that...

Regards,

Guillaume.

**********************************
Sent with HORDE/IMP




More information about the Snort-users mailing list