7-tcp-udp-pentesting-echo.md (1498B)
1 --- 2 title: "7/TCP/UDP - Pentesting Echo Service" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/7-tcp-udp-pentesting-echo.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/7-tcp-udp-pentesting-echo.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 7/TCP/UDP - Pentesting Echo Service 14 15 ## Basic Information 16 17 The Echo Protocol is a diagnostic service that returns received data to its sender. RFC 862 defines both a TCP service and a UDP service on port 7.<sup>[[1]](#references)</sup> 18 19 **Default ports:** 7/TCP and 7/UDP 20 21 ```text 22 PORT STATE SERVICE 23 7/udp open echo 24 7/tcp open echo 25 ``` 26 27 An exposed UDP echo service can participate in a denial-of-service loop if it is made to exchange traffic with another UDP character-generating service. CERT's advisory recommends disabling unnecessary UDP diagnostic services and filtering spoofed traffic.<sup>[[2]](#references)</sup> 28 29 ## Contact the UDP Echo Service 30 31 ```bash 32 nc -uvn <IP> 7 33 Hello echo # Sent by the client 34 Hello echo # Returned by the server 35 ``` 36 37 ## Shodan 38 39 ```text 40 port:7 echo 41 ``` 42 43 ## References 44 45 - [1] [RFC 862 - Echo Protocol](https://datatracker.ietf.org/doc/html/rfc862) 46 - [2] [CERT Advisory CA-1996-01 - UDP Port Denial-of-Service Attack](https://insights.sei.cmu.edu/documents/503/1996_019_001_496172.pdf)