 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| reply to R2
Re: Nachi the new champion bad boy A regular ping has as packet data:
abcdefghijklmnopqrstuvwabcdefghi
whereas in a Nachi ping the packet contents are:
ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª
Note this is supposed to Ascii character 'AA' but it doesn't display correctly in the posting (it is also known as a 'CyberKit ping').
Also note the length of the packet data is different as well.
I'm sure the author of the Nachi worm did this by design as it allows you identify Nachi infected systems by the content (and size) of the ping packet.
Blake -- »www.SonicLogger.com - Logging Software for SonicWall and 3Com »www.LinkLogger.com - Logging Software for Linksys, Netgear and Zyxel |