Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 6th, 2012, 09:56 AM
gslabbert5119 gslabbert5119 is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 6
Default MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

I just upgraded to ESET security suite V5.0.95.0
I keep keep getting this warning "Detected covert channel exploit in ICMP packet"
OS Windows 7 Pro SP1 64bit

I looked up the message and I am told that I should have personal firewall version newer than "1047", well I have version "1071" as per the modules so that should not be an issue.

I have opened up a ticket but I cant wait 24 hours for a response, for this message every 3 minutes is really annoying.

Thanks for the help

My modules are as follows ...
Virus signature database: 6772 (20120106)
Update module: 1037 (20110921)
Antivirus and antispyware scanner module: 1333 (20111215)
Advanced heuristics module: 1121 (20111208)
Archive support module: 1138 (20111214)
Cleaner module: 1052 (20111129)
Anti-Stealth support module: 1026 (20110628)
Personal firewall module: 1071 (20110912)
Antispam module: 1019 (20111213)
ESET SysInspector module: 1221B (20110623)
Self-defense support module: 1018 (20100812)
Real-time file system protection module: 1006 (20110921)
Translation support module: 1034 (20111214)
HIPS support module: 1026 (20110725)
Internet protection module: 1025 (20110929)
Web content filter module: 1009 (20110705)
Advanced antispam module: 1019 (20111202)
Database module: 1016 (20110726)
  #2  
Old January 6th, 2012, 10:06 AM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,224
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

The detection is correct. You must have software installed that exploits ICMP for transmitting non-standard data. A Wireshark pcap log with the communication captured may shed more light.
  #3  
Old January 6th, 2012, 10:09 AM
gslabbert5119 gslabbert5119 is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 6
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

I did not get this until this morning when I upgraded from v4 to v5.
  #4  
Old January 6th, 2012, 10:57 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

Quote:
Originally Posted by Marcos
The detection is correct. You must have software installed that exploits ICMP for transmitting non-standard data. A Wireshark pcap log with the communication captured may shed more light.

Could you also post few software that use that tactic? It might help user to narrow it down.
as in
http://www.wilderssecurity.com/showp...0&postcount=19
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #5  
Old January 6th, 2012, 02:10 PM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,224
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

For instance, Battlefield 3. For this one, we'll make an exception in the next build of the firewall module.
  #6  
Old January 6th, 2012, 02:50 PM
gslabbert5119 gslabbert5119 is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 6
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

I dont play any computer games on any of my computers, I am just not a gamer, the computer is strictly work related, and the software on the computer is either a Microsoft product, SQL Server or an Oracle product related to OBIEE. I have a computer and a laptop, each running the same software, on the PC I have CS5.0.94.0 and I am not having any issues, on the laptop I am running CS5.0.95.0 and am having this issue.

I run Google Talk on both computers and that is the only 3rd party software that is used.
  #7  
Old January 9th, 2012, 05:08 AM
adza adza is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 35
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

Maybe I can be of assistance.

Written with Delphi 2007 and Indy's TIdICMPClient

xttp://www.jvxp.com/temp/EsetPingProject1.exe

This project simply puts out a ICMP request through to Google's server 8.8.8.8

Very simple (Threw together in seconds) so doesn't even display the result - but it should raise the red window that you see.

Hope this is of help...

Adza

Last edited by Cudni : January 9th, 2012 at 05:35 AM. Reason: disabled link to unknown .exe
  #8  
Old January 15th, 2012, 06:20 PM
RonS RonS is offline
Infrequent Poster
 
Join Date: Jan 2004
Posts: 2
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

Quote:
Originally Posted by gslabbert5119
I just upgraded to ESET security suite V5.0.95.0
I keep keep getting this warning "Detected covert channel exploit in ICMP packet"
OS Windows 7 Pro SP1 64bit

I looked up the message and I am told that I should have personal firewall version newer than "1047", well I have version "1071" as per the modules so that should not be an issue.

I have opened up a ticket but I cant wait 24 hours for a response, for this message every 3 minutes is really annoying.

Thanks for the help

My modules are as follows ...
Virus signature database: 6772 (20120106)
Update module: 1037 (20110921)
Antivirus and antispyware scanner module: 1333 (20111215)
Advanced heuristics module: 1121 (2011120
Archive support module: 1138 (20111214)
Cleaner module: 1052 (20111129)
Anti-Stealth support module: 1026 (2011062
Personal firewall module: 1071 (20110912)
Antispam module: 1019 (20111213)
ESET SysInspector module: 1221B (20110623)
Self-defense support module: 1018 (20100812)
Real-time file system protection module: 1006 (20110921)
Translation support module: 1034 (20111214)
HIPS support module: 1026 (20110725)
Internet protection module: 1025 (20110929)
Web content filter module: 1009 (20110705)
Advanced antispam module: 1019 (20111202)
Database module: 1016 (20110726)

I upgraded to ESS about 10 days ago but just experienced the same thing today ...after a brief power outage , (at which time my UPS came on ). After poking around in ESS setup I found that for some unknown reason ESS became reconfigured...possibly because of the power outage...and it changed the "Computer protection mode in network" from "Allow sharing" to "Strict protection." As soon as I changed it back to "Allow sharing I stopped getting the warning for all computers, printer and external hard drive on my network.
  #9  
Old February 2nd, 2012, 08:45 AM
S3curityPlu5 S3curityPlu5 is offline
Infrequent Poster
 
Join Date: Feb 2012
Location: UNited States
Posts: 4
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

Yes this message is usually when other networked or workgroup computers try to link up to your computer with eset set on this Strict option. I also just realized the same problem, and i have a SOHO network that I use for sharing, well I did not change the option but it must have changed itself since I just rebooted.
  #10  
Old February 2nd, 2012, 04:34 PM
adza adza is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 35
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

For me I have eset set to allow sharing - yet the problem still occurred with other pinging apps.
  #11  
Old April 10th, 2012, 01:36 PM
foneil foneil is offline
Eset Moderator
 
Join Date: Dec 2010
Location: San Diego
Posts: 255
Default Re: MEssage: Detected covert channel exploit in ICMP packet Eset v5.0.95.0

Please note that we have updated the ESET Knowledgebase article for this issue:There are two solutions.

Use solution 1 if you want to disable notifications so that you no longer receive pop-ups each time an attack is detected.

Use solution 2 if this issue is preventing a network-aware application or game from functioning properly and your Personal firewall module is up to date.
__________________
ESET Knowledgebase Technical Writer
Wilders ESET Moderator

Resources for online help: ESET Knowledgebase

@ESETNA (Twitter) | ESETKnowledgebase (YouTube)
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:22 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums