1 icmp vulnerability, 2 illegal commands (netbios and smtp), Figure 33 smurf attack – ZyXEL Communications ZyXEL ZyWALL P1 User Manual

Page 97

Advertising
background image

ZyWALL P1 User’s Guide

96

Chapter 6 Firewalls

Figure 33 Smurf Attack

6.4.2.1 ICMP Vulnerability

ICMP is an error-reporting protocol that works in concert with IP. The following ICMP types
trigger an alert:

6.4.2.2 Illegal Commands (NetBIOS and SMTP)

The only legal NetBIOS commands are the following - all others are illegal.

Table 27 ICMP Commands That Trigger Alerts

5

REDIRECT

13

TIMESTAMP_REQUEST

14

TIMESTAMP_REPLY

17

ADDRESS_MASK_REQUEST

18

ADDRESS_MASK_REPLY

Table 28 Legal NetBIOS Commands

MESSAGE:

REQUEST:

POSITIVE:

NEGATIVE:

RETARGET:

KEEPALIVE:

Advertising