Question: A server at a company was compromised with malware. The company is protected with a firewall that blocks all traffic except for the following protocols:
A server at a company was compromised with malware. The company is protected with a firewall that blocks all traffic except for the following protocols: ICMP, DNS, and HTTP/HTTPS (80/443).
a. Using only the ICMP protocol, the attacker wants to create a bi-directional connection for command and control. Explain how the attacker can do that using only the ICMP protocol.
Step by Step Solution
3.44 Rating (151 Votes )
There are 3 Steps involved in it
If a server at a company has been compromised with malware it is important to take immediate action to mitigate the risks and prevent further damage Here are some steps you can take 1 Isolate the comp... View full answer
Get step-by-step solutions from verified subject matter experts
