Recommended Posts

i was trying to run tracert to see how bad my connection is to a particular site... but i end up with no packets all along the hops... so i messed around with my modem router and made it accept all icmp packets, and now i can tracert properly... then i tried to go to dslreport's 'tweak tester' which needs to ping my computer, and i had to allow icmp packets through windows firewall for that to work too

so i was wondering, why do the firewalls block icmp packets in the first place? is it ok for me to leave icmp packets open 24/7?

Link to comment
https://www.neowin.net/forum/topic/678868-is-icmp-dangerous/
Share on other sites

Ping allows you to see if the host is up, so it's an easy way to see if there's a computer at an IP address. Knowing there's a computer there means you can focus on breaking into it.

And ping of death and such.

Personally I leave ICMP alone, The firewall config is default but it's still pretty good by default (Only allow connections if it already has a relationship to my computer, so my PC has to start the communication)

Home routers/firewalls block icmp by default because they do not pay attention to the RFC's and some people actually think it protects them from stuff or makes their machine harder to find :rolleyes:

Can bad stuff be done with certain aspects of ICMP -- sure, but it also is required for things to function correctly. If you want to correctly secure your network. Then block the bad aspects of ICMP, the parts you do not need, but allow the required portions and the stuff you want to use. ICMP is a lot more then ping ;)

Blocking type 3 icmp can cause all kinds of connectivity issues. These are you destination not reachable, and frag needed but DF set, etc. As you found out type 11 is needed for traceroute to work -- ie TTL 0 during transit kind of required to find the different hops now isnt it ;)

I would suggest you get a router that allows you the fine control so you can do it the right way.. Rate control of ICMP for example would protect you against a icmp based DOS. You would normally block fragmented ICMP, etc.. etc..

A simple google will find you all kinds of guides on what aspects of ICMP to allow and or deny.. Here is a fairly decent guide that goes over the different types and codes of ICMP.. Which ones to block which to allow, etc.

http://www.daemon.be/maarten/icmpfilter.html

Here is another http://www.cymru.com/Documents/icmp-messages.html

And another http://www.bsi.bund.de/english/gshb/manual/s/s05120.htm

These are just a few examples going over the different types and codes of ICMP, what you might want to filter and what you should not, etc. There are many many guides.. But anything that tells you should should block all ICMP is just plain asinine and will cause you way more issues than any type of protection it might provide..

I have to wonder when was the last time your home ISP connection was hit with a icmp based DOS ;) So what if worm X looking to exploit you can get an echo back from your public IP -- who really gives a rats ass??? Your router/firewall is not going to allow the traffic it might try sending your way anyway.

If you router/router does not allow you the fine control to correctly manage what ICMP you can allow or not allow -- then allow it for sure.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft finally admits its default Windows 11 25H2, 24H2 action broke key legacy component by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. So far the company has acknowledged two known issues that have popped up after the release which include bugged-out Office apps as well as the Recycle Bin; though there could be more at play too. Speaking of bugs and issues, Microsoft seems to have finally acknowledged a problem that probably has been around for close to a year. That's because back in July of 2025 the company made a default change to the latest Windows 11 versions, wherein it switched to JScript9Legacy on Windows 11 24H2 and later releases. Hence following the release of version 25H2 in October 2025, JScript9Legacy also remained default-enabled. As a result there has been a compatibility issue ever since then. For those wondering, by switching to JScript9Legacy Microsoft intended to improve the security of modern Windows PCs by reducing vulnerabilities tied to legacy scripting like cross-site scripting (XSS), among others. XSS exploits can allow cyber-attackers to attach malicious code onto legitimate websites and use them to execute the code when a potential victim loads such a website. Hence the new JScript9Legacy engine enforced stricter execution policies and improved object handling, which should help mitigate such attacks. Microsoft today has published a new support article detailing the problem. Neowin spotted it while browsing. The company says that JScript global definitions and execution context may fail to persist across scripts, potentially breaking older dependent apps and web-based components that relied on this legacy behavior. In the article Microsoft has confirmed that the issue stems from its move away from the older jscript9.dll engine in favor of jscript9legacy.dll. As mentioned above, while the newer engine was designed to address vulnerabilities and strengthen security it also changes how JScript handles execution context. As a result functions and definitions loaded by one script could no longer remain available to subsequent scripts once execution ended. The company notes that some applications worked correctly on earlier Windows versions because the older JScript engine automatically retained global definitions and execution state between scripts. Under the newer model though that behavior is disabled by default causing certain legacy workloads and polyfill-dependent scripts to fail. Microsoft says it addressed the problem via the KB5077241 update though the fix had not been enabled automatically in the following updates. As such admins must explicitly turn on persistent JScript execution context using a Registry setting that the tech giant shared today. The configuration can be applied to individual processes or system-wide through the FEATURE_ENABLE_PERSISTENCE registry key. The steps have been outlined below: Run the following command to create the feature control registry key: reg add "HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PERSISTENCE" Under this key, create a new DWORD (32-bit) value. Configure the value as follows: To enable persistence for specific processes only: Set the value to 1 for each target process name. To enable persistence for all processes: Add * as the key name and set its value to 1. You can find the official support article here on Microsoft's website.
    • The possibility that milk gathers back into a glass implies that gravity can be 'reversed'.
    • VidCoder 12.20 by Razvan Serea  VidCoder is a DVD/Blu-ray ripping and video transcoding application for Windows. It uses HandBrake as its encoding engine. Calling directly into the HandBrake library gives it a more rich UI than the official HandBrake Windows GUI. VidCoder can rip DVDs but does not defeat the CSS encryption found in most commercial DVDs. You’ll need the NET 8 Desktop Runtime. If you don’t have it, VidCoder will prompt you to download and install it. The Portable version is self-contained and does not require any .NET Runtime to be installed. You do not need to install HandBrake for VidCoder to work. Feature list: Multi-threaded MP4, MKV containers Completely integrated encoding pipeline: everything is in one process and no huge intermediate temporary files H.264, H.265, MPEG-4, MPEG-2, VP8, Theora video Hardware-accelerated encoding with AMD VCE, Nvidia NVENC and Intel QuickSync AAC, MP3, Vorbis, AC3, FLAC audio encoding and AAC/AC3/MP3/DTS/DTS-HD passthrough Target bitrate, size or quality for video 2-pass encoding Decomb, detelecine, deinterlace, rotate, reflect, chroma smooth, colorspace filters Powerful batch encoding with simultaneous encodes Customizable Pickers to automatically pick audio and subtitle tracks, destination, titles and more Instant source previews Creates small encoded preview clips Pause, resume encoding VidCoder 12.20 changes: Updated HandBrake core to 1.11.2. Download: VidCoder 12.20 | 47.0 MB (Open Source) Download: Portable VidCoder 12.19 | 89.3 MB Link: VidCoder Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Too soon, I'm still not over this death!
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      593
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      77
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!