Re: possible causes of source and destination ip from external network

From: Tony Rall (trall_at_almaden.ibm.com)
Date: 06/22/04

  • Next message: Frank Knobbe: "Re: ssh and ids"
    To: focus-ids@securityfocus.com
    Date: Mon, 21 Jun 2004 19:47:46 -0700
    
    

    On Saturday, 2004-06-19 at 22:09 ZE8, "Annie Green"
    <annie_r_green@hotmail.com> wrote:
    > What would be the possible causes of the IDS alert that shows source ip
    and
    > destination ip from external network? Also, why did the router route
    this
    > packet in the first place?

    An extremely remote possibility is that source routing was used to direct
    external source traffic through your network (but you really shouldn't be
    allowing source routed packets into your network). But what is much more
    likely is that you have a machine on your net using the wrong IP address.
    One example of that is a simple misconfiguration (a machine was used on
    some other network and then erroneously connected to your network without
    changing its config). And then it could be an infected machine spoofing
    the source address.

    Tony Rall

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Frank Knobbe: "Re: ssh and ids"

    Relevant Pages

    • Re: How is DNS resolution working?
      ... >> and our DNS server on machine B is only on a private network, ... host on the external network ... It just happens that on the external network, there is a Windows domain ...
      (microsoft.public.win2000.dns)
    • Re: How is DNS resolution working?
      ... >> and our DNS server on machine B is only on a private network, ... host on the external network ... It just happens that on the external network, there is a Windows domain ...
      (microsoft.public.win2000.networking)
    • RE: WIN2003 server and SBS2000 AD/DC
      ... First of all, I would confirm your network diagram, is it like follow? ... DMZ as the external network) on the SBS. ... Publish an Internal Web Server Through Microsoft ISA Server 2000 ... Microsoft - Server publishing rules and IP packet filters ...
      (microsoft.public.windows.server.sbs)
    • Re: WTF?? ISA 04 semantics inbound or outbound
      ... Think of the direction from the perspective of the From network. ... the traffic is outbound from the External network, ... A helicopter with a pilot and a single passenger was flying around above ...
      (microsoft.public.windows.server.sbs)
    • Re: WTF?? ISA 04 semantics inbound or outbound
      ... Think of the direction from the perspective of the From network. ... the traffic is outbound from the External network, ... A helicopter with a pilot and a single passenger was flying around above ...
      (microsoft.public.windows.server.sbs)