Apple large ping attack debunk

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Apple large ping attack debunk

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Apple large ping attack debunk
Apple large ping attack debunk
2023-04-11 06:11:29
Tags: #large ping attack

you probably face this issue on all apple products. as a member of this forum, i've seen a lot of people talking about "false alarm" from the large ping attack that resulted from apple products.someone analyzed and located it to apple devices. 
well, i recently came across some articles about this. 
apple introduced a new mechanism back in ios 13. at that time, they added a new feature to actively detect your internet connection by randomly ping-ing their domain to test your connectivity. it's probing. 
what i dug from the article is that: netcts.cdn-apple.com 
apple products ping it at a rather large packet size and this triggers the alarm on omada gateway.
i searched this around but i don't see a lot of people mentioning this domain. i am not sure if it is active or not on ios 16. but it explains why you see large ping attacks from apple products.
so, it is not a true threat. and something can be done to get this better fixed. like a white list on the ping test? 
 

btw, does anyone know an official article or explanation from apple about this probing feature? i did not search on apple docs. maybe this is a dev blog? apple seems never released any details about this. it's a feature builtin to all apple devices since ios 13. 

ScReW yOu gUyS. I aM GOinG hoMe. —————————————————————— For heaven's sake, can you write and describe your issue based on plain fact, common logic and a methodologic approach? Appreciate it.
  1      
  1      
#1
Options
2 Reply
Re:Apple large ping attack debunk
2023-04-12 16:06:41

  @Tedd404 

 

Hey Ted

 

You came to the same result as me then, spent some time tracking this error a few months back and PCAPs all pointed to the apple cdn pings, the timings where too close to ignore

 

Think you hit the nail on the head, personally I have just been ignoring these for months now lol..

  0  
  0  
#2
Options
Re:Apple large ping attack debunk
2023-04-13 05:32:35

  @Tedd404 

 

I have the same "Problem" with Amazon since the latest Firmware (1.3.0 ER7206).

 

For Example: 13.208.223.143 (use whois)

 

Some days I get 50 notifications, some days 0, thats randomly.

I have about 8 echos at home.

 

 

 

  0  
  0  
#3
Options