SCAN: Xprobe ICMP ECHO with Bad ICMP Code

This signature detects an ICMP Echo Request packet generated by the Xprobe scanner. Attackers can use this packet during an Xprobe scan to determine the operating system running on the target host. Attackers can use this information to plan future, more targeted attacks.

Extended Description

This signature detects ICMP Echo Request packets with a legitimate ICMP type, except with bad ICMP code, sent by Xprobe. Remote attackers could use Xprobe to view confidential information to prepare for further attacks.

Short Name
SCAN:XPROBE:XPROBE-BADCODE
Severity
Warning
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
Bad Code ECHO ICMP Xprobe with
Release Date
05/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3815
Port
ICMP
False Positive
Unknown

Found a potential security threat?