Re: mystery martian source from 127.0.0.1



EricT wrote:
Tauno Voipio wrote:

The reported address contains both the Ethernet source address
(00:09:7b:8d:98:70) and the IP protocol identifier (08:00).

Try to find the hardware with the Ethernet address above.



Thanks a lot Tauno,

this HWAddr does not belong to my LAN.
Is it the receiver or the sender address of the packet? If it is the
receiver address, how comes localhost is knowing about it?

Fairly probably the sender address - cannot say for sure. To be of any use, it should be in the same LAN with you.

Are you in the hispeed.ch DSL network?  If yes, it's probably
a misconfigured / infected host in the same network. The reported
source address is 80-219-238-182.dclient.hispeed.ch.

You could set up iptables to trap and log all packets with
the IP address 80.219.238.182.

HTH

--

Tauno Voipio
tauno voipio (at) iki fi
.



Relevant Pages

  • Re: Van Jacobsons net channels and real-time
    ... packages with real-time latencies. ... Finding the end point in the receive interrupt and send of the packet to ... through soft irq which might be busy working on IP packages. ... Each end receiver provides his own receive resources. ...
    (Linux-Kernel)
  • Re: Converting C++ header file to Delphi4 pas unit
    ... > component for long lines and situations where the transmitter and receiver ... If you choose the right PCI card, ... > can probably see that the issue of baudrate and packet size is critical. ... > not you can only get the approximate baud rate you are after. ...
    (comp.lang.pascal.delphi.misc)
  • Re: CSocketFiles / CArchive vs Raw Buffer Manipulation
    ... such as network packet transmission. ... UDP within a LAN often gives the effective illusion that it is reliable. ... fail without warning of any sort to either the sender or the receiver. ...
    (microsoft.public.vc.mfc)
  • We have lots of users with SonicWalls for VPN connectivity in to FW-1, possible major security hole
    ... With default rule disabled: Disable default Src: LAN Dst: ALL ... The firewall WAN address is 24.184.168.52 ... A NT server on the internal LAN is 192.168.1.22 ... why is my internal server responding to this packet as a "Destination ...
    (Incidents)
  • Re: AES MAC security question
    ... >> compute overhead for the receiver by a lot. ... >> is that anyone who looks at information coming from the keeloq system ... >> particularly compelling marketting advantage to the encryption. ... > then checks the MAC of the decrypted packet. ...
    (sci.crypt)