Hello Alexey,
On 07 Sep 26 16:57, you wrote to me:
Hello Michiel!
On Mon, 07 Sep 2026 15:22 +0200, you wrote to me:
Still, if I wanted to spam someone with responses to PING, I
could use such "vulnerability".
And the gain of such an action would be?
Would you ask the same question to a security audit of your company network infrastructure or something like that?
1) You'r not answering the question.
2) Knowing the motives of the attacker is usefull when designing a defence.
When a potential vulnerability arises one should always ask the following questions:
1) What has the potential attacker to gian?
2) What have the attacked to loose?
3) Is the proposed defence effective
4) How does the proposed defence interfere with normal operation?
My toilet hs little defince against unauthorised use? Of course I can take measures to make unauthorised use difficult or maybe even impossible. I can put locks on the door, even more than one lock. Two Factor Authorisation. But the effect will be tha I mainly make it moe difficult for myself. It os just not worth doing all that just to prevent occasional unaithorised use.
The same goes for PING over unsecure links. It isn't really a vulnerabilty. Nothing much will happen if someone triggers a ping or a series of pings from a spoofed source. Plus that only using ping via secure links doesn't make it impossible. And it interferes with ping being a usefull tool.
Look, I once had a mail bomb. VIA A SECURE LINK. The secure link did not protect me. OTIH, I have had PING anabled for decades. Including vis unsecure links. Never had a problem.
Someone may want to do that just because they can. If there is an exploitable vulnerability, it will be exploited some day.
There is nothing to "exploit". There is no problem with PING over unsecure links. PING is usefull to explore the routing. Secure or unsecure. It does jsut that. Don't fix what aint broke.
Cheers, Michiel
--- GoldED+/W32-MINGW 1.1.5-b20260904
* Origin:
http://www.vlist.eu (2:280/5555)