ICMP IP 'ID' Field Error Message Probe
CAPEC-332 · Detailed · Stable
An adversary sends a UDP datagram having an assigned value to its internet identification field (ID) to a closed port on a target to observe the manner in which this bit is echoed back in the ICMP error message. This allows the attacker to construct a fingerprint of specific OS behaviors.
likelihood: Medium
severity: Low