Can anyone tell me if allowing type 11 ICMP (time exceeded) to a network will make it vulnerable to Smurf Attacks? I know that Smurf Attacks use echo/icmp, but is it possible to do one with type 11? I am going through our IDS' events and we have seen some possible Smurfs. I am not vulnerable to echo/icmp, but I just wanna double check on type 11. Thanks in advance.




Reply With Quote