RE: Bizarre traffic



A bad NIC is one of the other possibilities on my list.

I have difficulty imagining a router or switch doing this
*only* to a specific client machine.

David Gillett


-----Original Message-----
From: Brian Rectanus [mailto:brectanu@xxxxxxxxx]
Sent: Friday, February 10, 2006 9:15 PM
To: incidents@xxxxxxxxxxxxxxxxx
Subject: Re: Bizarre traffic

With it cooresponding to network disruptions, similar IPs on
your net and conversations looking normal otherwise, have you
considered it a router/switch corrupting packets? Or even
the a bad NIC in a machine?

-B

On 2/9/06, David Gillett <gillettdavid@xxxxxxxx> wrote:
Does anybody know of anything (malware, hackware, other?)
that would
cause a machine to put out traffic with the first octet of the
destination address (re)set to ZERO?

The traffic I saw all was headed for port 443, and wasn't
decipherable. The variation in packet size looked like a real
conversation, although return packets (if any) weren't passing my
sniffer. The destination addresses, sans the bogus first octet,
looked like addresses of a couple of real internal servers (source
address was internal) -- which, however, do not have HTTPS service
active.

[This traffic correlated with various intermittent disruptions of
our network, which stopped when the source machine dropped off the
network. It later reappeared -- and so did a brief
disruption -- long
enough for me to pinpoint and ban it.]

David Gillett







Relevant Pages

  • Re: Weird net connection problem
    ... across the Internet) to throttle or not the traffic). ... Depends how many packets in your connection are lost. ... you connect to some ISP via a router (not a home ADSL one, I should add, ... be advertising to the rest of the Internet, the address of your network, ...
    (uk.comp.sys.mac)
  • Re: Strange networking problems after update 5.2.1->5.3
    ... I cannot ping it even from a host connected to the same ... My network at home is somewhat simpler (192.168.1.0/24 is local, ... is another notebook that is acting as NAT and default router). ... not even the obviously outgoing ping packets. ...
    (freebsd-stable)
  • Re: Nmap questions concering my router
    ... It's a bit off topic - but down at the Ethernet level, the packets are ... so your router masquerades for you. ... it may differ from other applications - we just send data to a network ... >> the Ethernet header is the MAC address of the 10.0.0.138 interface. ...
    (comp.security.firewalls)
  • Re: Setting up Airport Express
    ... from your local network to the internet. ... My Ethernet switch routes packets too, ... a router understands IP and knows how to forward IP ...
    (uk.comp.sys.mac)
  • Re: Production use of carp?
    ... One less-documented feature of VMware ESXi is that it checks whether it's isolated from the network by pinging the gateway on the management network. ... The router can discard/drop inbound ... ICMP packets directed at the router itself (e.g. a destination IP of the ...
    (freebsd-net)