RE: possible causes of source and destination ip from external network
From: Tom Arseneault (TArseneault_at_counterpane.com)
Date: 06/22/04
- Previous message: Murtland, Jerry: "RE: ssh and ids"
- Maybe in reply to: Annie Green: "possible causes of source and destination ip from external network"
- Next in thread: Tony Carter: "Re: possible causes of source and destination ip from external network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 21 Jun 2004 18:17:55 -0700 To: "Annie Green" <annie_r_green@hotmail.com>, <focus-ids@securityfocus.com>
One possibility is a host on your network has been compromised and it
being used by an attacker to send out spoofed packets. You'd need to
check the MAC addresses on the packets and see if you can track down
where their coming from then quarantine that machine.
Thomas J. Arseneault
Security Engineer
Counterpane Internet Security
tarseneault@counterpane.com
> -----Original Message-----
> From: Annie Green [mailto:annie_r_green@hotmail.com]
> Sent: Saturday, June 19, 2004 7:09 AM
> To: focus-ids@securityfocus.com
> Subject: possible causes of source and destination ip from
> external network
>
> Hi all
>
> What would be the possible causes of the IDS alert that shows
> source ip and destination ip from external network? Also, why
> did the router route this packet in the first place?
>
> Regards,
> A.
>
> _________________________________________________________________
> Get MSN Hotmail alerts on your mobile.
> http://en-asiasms.mobile.msn.com/ac.aspx?cid=1002
>
>
> --------------------------------------------------------------
> -------------
>
> --------------------------------------------------------------
> -------------
>
---------------------------------------------------------------------------
---------------------------------------------------------------------------
- Previous message: Murtland, Jerry: "RE: ssh and ids"
- Maybe in reply to: Annie Green: "possible causes of source and destination ip from external network"
- Next in thread: Tony Carter: "Re: possible causes of source and destination ip from external network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|