Re: BAD TRAFFIC 0 ttl

From: Will Tell (nosphie@rootshell.be)
Date: 08/23/02


Date: 23 Aug 2002 19:45:15 -0000
From: Will Tell <nosphie@rootshell.be>
To: incidents@securityfocus.com


('binary' encoding is not supported, stored as-is) In-Reply-To: <20020823131552.871DE3951@sitemail.everyone.net>

Hey Seren,
looks like you have the tcpdump file of the happening.
In this case u should look not for the IPs but for the MAC.
I had a case like this and all the IPs had the same MAC.
So take for exemple "ettercap" in file offline mode and
sniff only in MAC mode.
Might be that clear up something.

Will Tell

<20020823131552.871DE3951@sitemail.everyone.net>
>
>Hello all,
>
>I've had this same pattern of traffic appear inside my
network on four different occasions and I've found no
answer as to what it is, I'm hoping someone here has
seen something similar.
>
>This always happens over the midnight hour. The only
things that vary are the length of time and number of
different destination IPs. The destinations are always
#.0.1.15. The source is usually 218 or 65.0.1.0, but
always #.0.1.0. The packet data is always the same.
>
>Samples follow. Any thoughts are greatly appreciated.
>
>Thanks!
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: SNORT: MAC Address Alert
    ... Once the users acquire the known IPs you can track their ... Subject: SNORT: MAC Address Alert ... > Captus Networks IPS 4000 ... > Intrusion Prevention and Traffic Shaping Technology to: ...
    (Focus-IDS)
  • Re: 14 octet MACs and security
    ... And many thanks to Tauno for explaining the MAC for me. ... accompanying problem is that I have 2 WAPs at opposite ends of the ... IPs that are on an alert list to email me their activity. ... these connections are timing out. ...
    (comp.os.linux.networking)
  • 3com AP2000 (3CRWE20096A) web-based setup
    ... server running on my machine, set to assign IPs between 192.168.0.2 and ... It isn't listening on any of those IPs. ... server, which seems to be running fine, and how do I find out the MAC ... Adam Short - ajs at orinoco dot homelinux dot org ...
    (comp.os.linux.networking)
  • Re: Wired captive portal pen-test
    ... switch-router so you will not be able to see any ... I saw ARP requests coming from the router and asking for the MAC of several other IPs of the same segment where my laptop was connected ... try connecting your laptop to the phone's RJ45 and do a ...
    (Pen-Test)
  • OT: WOnder Bread Support
    ... >I use a cable modem ISP, ... >running Windows 98." ... computer is a Mac. ... >IPs that start with those numbers are used by Macs." ...
    (microsoft.public.cert.exam.mcse)