Short Name |
ICMP:EXPLOIT:DIFF-CSUM-IN-RESND |
---|---|
Severity |
Low |
Recommended |
No |
Category |
ICMP |
Keywords |
ICMP CHECKSUM DIFFERENT RESEND |
Release Date |
2003/08/27 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects an ICMP echo request retransmission (for example, with the same ID and sequence numbers) with a different checksum field. This can indicate data tunneling over ICMP.
Data tunneling over ICMP is often used to bypass firewalls that prevent outgoing TCP connections, but allow incoming and outgoing ICMP messages.