ICMP: Echo Request Resent w/Different Length

This protocol anomaly triggers when it detects an ICMP echo request retransmission (for example, with the same ID and sequence numbers) with different data length. This can indicate data tunneling over ICMP.

Extended Description

Matched ICMP ECHO REQUEST and ECHO REPLY packets whose data do not match are protocol anomalies. Their presence could indicate that a transmission error has occurred, or that data tunneling over ICMP is taking place.

Short Name
ICMP:EXPLOIT:DIFF-LEN-IN-RESND
Severity
Major
Recommended
False
Recommended Action
None
Category
ICMP
Release Date
08/27/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?