📄 469.txt
字号:
--Rule:--Sid:469--Summary:This event is generated when an ICMP ping typically generated by nmap is detected.--Impact:This could indicate a full scan by nmap which is sometimes indicative ofpotentially malicious behavior.--Detailed Information:Nmap's ICMP ping, by default, sends zero data as part of the ping.Nmap typically pings the host via icmp if the user has rootprivileges, and uses a tcp-ping otherwise. --Attack Scenarios:As part of an information gathering attempt, an attacker may use nmapto see what hosts are alive on a given network. If nmap is used forportscanning as root, the icmp ping will occur by default unless theuser specifies otherwise (via '-P0').--Ease of Attack:Trivial. Nmap requires little or no skill to operate.--False Positives:Possible. The only current identifying feature of nmap's ICMP ping isthat the data size is 0. It is entirely possible that other tools maysend icmp pings with zero data.Kontiki delivery manager used on windows platforms to downloadmultimedia files is known to produce ICMP pings that can cause thisrule to generate many events.avast! antivirus update feature is reported to produce ICMP pings withzero data when connecting to the avast servers. This can occur every 40seconds if no reply is received by the client.The avast! client attempts to ping one of the following servers:URL: http://www.asw.cz/iavs4proIP: 195.70.130.34URL: http://www.avast.com/iavs4proIP: 66.98.166.72URL: http://www.iavs.net/iavs4proIP: 207.44.156.15URL: http://www.iavs.cz/iavs4proIP: 62.168.45.69--False Negatives:None currently.--Corrective Action:If you detect other suspicous traffic from this host (i.e., aportscan), follow standard procedure to assess what threat this maypose. If you only detect the icmp ping, this may have simply been a'ping sweep' and may be ignored.--Contributors:warchild@spoofed.orgSourcefire Research TeamNigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:www.insecure.org--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -