RE: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)

From: greg@optionsinternet.com
Date: 01/30/03

  • Next message: Russell Fulton: "Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)"
    From: "greg@optionsinternet.com" <greg@optionsinternet.com>
    To: incidents@securityfocus.com
    Date: Thu, 30 Jan 2003 16:29:24 -0500
    
    

    Today we have been receiving on average 380,000 requests an hour TO
    255.255.255.255 FROM random IPs. I performed a reverse DNS query on a
    sample of 200 hosts, 2 of which came back with hostnames. A ping scan of
    the very same 200 hosts showed that only around 20 were *active*.

    I contacted our ISP and was told that this traffic was "normal".

    Has anyone else seen any similar requests?

    Regards

    Greg Bolshaw

    Original Message:
    -----------------
    From: Tomasz Papszun tomek-incid@lodz.tpsa.pl
    Date: Thu, 30 Jan 2003 19:03:51 +0100
    To: incidents@securityfocus.com
    Subject: Packets from 255.255.255.255(80) (was: Packet from port 80 with
    spoofed microsoft.com ip)

    On Thu, 30 Jan 2003 at 14:31:36 +1100, Keith Owens wrote:
    > On Wed, 29 Jan 2003 21:46:53 +1100,
    > Michael Rowe <mrowe@mojain.com> wrote:
    > >I received a packet on my cable modem today, allegedly from
    > >microsoft.com:
    > >
    > >18:41:35.663374 207.46.249.190.80 > my.cable.modem.ip.1681:
    S866282571:866282571(0) ack 268566529 win 16384 <mss 1460>
    >
    > I am seeing a lot of sync/ack packets from port 80 to non-existent
    > addresses on my networks. Somebody is spoofing source addresses to
    > attack hosts, we are just innocent victims. When will ISPs learn that
    > they should filter their customer's packets to prevent spoofing? I am
    > even seeing syn/ack packets from 255.255.255.255:80!
    >

    Similarly at my networks.
    Yesterday evening (Jan 29 21:10 GMT+1) a very noticeable stream of such
    packets started to come into my networks.

    All are TCP, from 255.255.255.255(80), destined to various random
    addresses (even not used) to various port numbers.

    This appearance is very noticeable. Before yesterday, single packets
    from 255.255.255.255 were coming in rate about one for three weeks.
    Since yesterday there have been about 1680 for 22 hours.

    -- 
     Tomasz Papszun   SysAdm @ TP S.A. Lodz, Poland  | And it's only
     tomek@lodz.tpsa.pl   http://www.lodz.tpsa.pl/   | ones and zeros.
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    --------------------------------------------------------------------
    mail2web - Check your email from the web at
    http://mail2web.com/ .
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    


    Relevant Pages

    • Re: [fw-wiz] Cisco VPN reconnection every 23 minutes
      ... of UDP packets going between the client and the VPN concentrator. ... crypto map outside_map 61 match address outside_61_cryptomap ... Global IPSec over TCP Statistics ... Encapsulate packet requests: 120048 ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Cisco VPN reconnection every 23 minutes
      ... of UDP packets going between the client and the VPN concentrator. ... Can you forward crypto config from the Cisco VPN concentrator? ... Global IPSec over TCP Statistics ... Encapsulate packet requests: 120048 ...
      (Firewall-Wizards)
    • Re: FreeBSD 7.1 tcp problem (syncache)?
      ... Completed 200 requests ... 31728 data packets ... 9740 connections closed ... segment rexmit in SACK recovery episodes ...
      (freebsd-net)
    • Re: jboss4 on freebsd
      ... requests for sfbufs delayed ... This output is in the same second as I see no buffer space available .. ... I'm experimenting with jboss4 cluster under freebsd 7. ... packets errs bytes packets errs bytes colls ...
      (freebsd-net)
    • Re: Wireless module bcm43xx in 2.6.17 kernel
      ... There is a line in dmesg that says "Cleared all keys" before the card starts sending out sending out dhcp requests, so I'm guessing that is what the problem is. ... I used a packet sniffer to see what was going on and my browser will send http get requests, the site will return a few packets, my browser will continue to send http requests on an intermittent bases because no response is recieved for a while, and then for every occasional packet that is returned in response to the http requests I will also get duplicate packets. ... The only problem I had with it was that every once in a while it would drop a connection if I let the connection sit idle for a while yet my wireless card was reporting a successful connection. ...
      (Debian-User)