anyone who saw this arp traffic?
From: Monty Ree (chulmin2_at_hotmail.com)
Date: 02/23/05
- Previous message: Lars Georg Paulsen: "Comparing linux distros."
- Next in thread: dissolved: "RE: anyone who saw this arp traffic?"
- Reply: dissolved: "RE: anyone who saw this arp traffic?"
- Reply: Ankush Kapoor: "Re: anyone who saw this arp traffic?"
- Maybe reply: Andrew Shore: "RE: anyone who saw this arp traffic?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: security-basics@securityfocus.com Date: Wed, 23 Feb 2005 01:40:43 +0000
Hello, all.
When I capture network traffic at server farm,I can see lots of arp
broadcast like below.
But there is no server which use 172.16.x.x ip address.
and curiously,
1. source ip and destination ip is same
2. more curiously, same traffic(source mac:0:10:dc:f1:f7:64 , source
ip:172.16.97.157) is seen at my office.
3. I can also see this traffic(source mac:0:10:dc:f1:f7:64 , source
ip:172.16.97.157 ) at other IDC.
Have you ever seen this traffic?
Thanks in advance.
10:15:26.759069 0:10:dc:f1:f7:64 Broadcast arp 60: arp who-has
172.16.97.157 (Broadcast) tell 172.16.97.157
10:15:26.803792 0:c:76:4e:4:c8 Broadcast arp 60: arp who-has 172.16.100.103
(Broadcast) tell 172.16.100.103
10:15:26.955878 0:c:76:4e:4:c8 Broadcast arp 60: arp who-has 172.16.100.103
(Broadcast) tell 172.16.100.103
10:15:26.967737 0:10:dc:f1:f7:64 Broadcast arp 60: arp who-has
172.16.97.157 (Broadcast) tell 172.16.97.157
_________________________________________________________________
°í.. °¨.. µµ.. »ç.. ¶û.. ¸¸.. µé.. ±â.. MSN ·¯ºê
http://www.msn.co.kr/love/
- Previous message: Lars Georg Paulsen: "Comparing linux distros."
- Next in thread: dissolved: "RE: anyone who saw this arp traffic?"
- Reply: dissolved: "RE: anyone who saw this arp traffic?"
- Reply: Ankush Kapoor: "Re: anyone who saw this arp traffic?"
- Maybe reply: Andrew Shore: "RE: anyone who saw this arp traffic?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|