ICMP Data Field Modified - What does it Mean?

Posted by Lucretius on Server Fault See other posts from Server Fault or by Lucretius
Published on 2011-11-30T06:40:53Z Indexed on 2011/11/30 17:59 UTC
Read the original article Hit count: 364

Normal ICMP Data fields are composed of a pretty standard 32 byte string of alphabet characters.

abcdefghijklmnopqrstuvwabcdefghi

I have captured a series of ICMP echo requests using WireShark with a modified Data field and I have no idea what it means. (Underscores represent spaces.)

abcdefghijklmnopprstuvwxyzabcdefghi

abcdefghijklmnoparstuvwxyzabcdefghi

__abcdefghijklmnopsrstuvwxyzabcdefghi

__abcdefghijklmnopsrstuvwxyzabcdefghi

__abcdefghijklmnopwrstuvwxyzabcdefghi

__abcdefghijklmnopdrstuvwxyzabcdefghi__

Note:

  • The position of the "q" character
  • The addition of "xyz"
  • The addition of spaces before and after the payload
  • When you look at the position of "q" horizontally it spells "passwd" which is a Linux/Unix command for changing a users password.

Any ideas?

© Server Fault or respective owner

Related posts about network-monitoring

Related posts about wireshark