Re: possible causes of source and destination ip from external network

From: Adam Baldwin (baldwnad_at_yahoo.com)
Date: 06/22/04

  • Next message: Ron Gula: "RE: IDS Testing tool"
    Date: Tue, 22 Jun 2004 06:57:57 -0700 (PDT)
    To: Annie Green <annie_r_green@hotmail.com>, focus-ids@securityfocus.com
    
    

    The better question to ask is why is this packet on my
    network? As the question you asked is to ambiguous to
    answer with the information provided. There could be
    many reasons for triggering the alert.

    I would initially think that it is a packet with a
    spoofed source that originated from the inside of your
    network but it could also be misconfiguration or
    routing errors by your service provider.

    Routers / firewalls should be configured to drop
    anything not sourced from your internal network. That
    helps protect others networks from spoofed packets
    leaving your network. Don't want to be the source of
    an attack now do we? ;-)

    -Adam

    > What would be the possible causes of the IDS alert
    > that shows source ip and
    > destination ip from external network? Also, why did
    > the router route this
    > packet in the first place?

            
                    
    __________________________________
    Do you Yahoo!?
    New and Improved Yahoo! Mail - 100MB free storage!
    http://promotions.yahoo.com/new_mail

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Ron Gula: "RE: IDS Testing tool"

    Relevant Pages

    • alt.2600 FAQ Revision .014 (2/4)
      ... One type of firewall is the packet filtering firewall. ... Dropping packets instead of rejecting them greatly increases the time required to scan your network. ... Port scanning UDP ports is much slower than port scanning TCP ports. ... Chartreuse Use the electricity from your phone line Cheese Connect two phones to create a diverter Chrome Manipulate Traffic Signals by Remote Control ...
      (alt.2600)
    • RE: Freebsd Theme Song
      ... from the network into the ethernet receiver. ... It takes a certain amount of time to get the packet out of ... At low data rates polling is less ... >Subject: Re: Freebsd Theme Song ...
      (freebsd-questions)
    • Re: [9fans] Do we have a catalog of 9P servers?
      ... network layer data units, ergo, NAT again. ... The "packet ...
      (comp.os.plan9)
    • Re: very slow convergence of ntp to correct time.
      ... Many years ago the Proteon routers dropped the first packet ... David> after the cache timed out; ... cause issues for others when they are reconfiguring part of the network. ...
      (comp.protocols.time.ntp)
    • Re: [PATCH 1/1] network memory allocator.
      ... Kevent network AIO uses usual alloc_skb, naio is called when packet is ... data and main system can work with that free memory. ... You do not see the point of network tree allocator. ...
      (Linux-Kernel)