Skip to main content
kinmun
New Member
May 25, 2017
Question

traceroute intrusion detected

  • May 25, 2017
  • 1 reply
  • 6416 views

i have some windows 10 client getting the following traceroute intrusion.

what should i do ?

or i can just ignore them since the threat level is low.

destination is some site in microsoft.com

 

    1 reply

    kinmun
    kinmunAuthor
    New Member
    June 14, 2017

    how do i prevent/block these 2 clients from doing the traceroute/icmp "attacks" ?

    i have already create a rule to block traceroute and icmp for these 2 clients.

     

    kinmun
    kinmunAuthor
    New Member
    April 3, 2018

    its says related to CVE-1999-0525.

    traceroute packet.

    is it really harmless 

     

    kurtli_FTNT
    Staff
    Staff
    April 3, 2018

    Hi there, 

       According to the fortiguard/IPS, this is a low level problem. So if you've setup a rule on FGT to block these 2 PCs traceroute, then this information gathering stopped. If this problem happens constantly, for the root cause, you probably need to dig into these two windows to find out which process/daemon or even malware is sending out this probe.  Suggest to download a forticlient to scan the entire computer to see if anything wrong.

     

     

    Thanks