Re: mystery martian source from 127.0.0.1



Tauno Voipio wrote:
> Fairly probably the sender address - cannot say for sure.
> To be of any use, it should be in the same LAN with you.
>
> Are you in the hispeed.ch DSL network? If yes, it's probably
> a misconfigured / infected host in the same network. The reported
> source address is 80-219-238-182.dclient.hispeed.ch.
>
> You could set up iptables to trap and log all packets with
> the IP address 80.219.238.182.
>
> HTH
>


80-219-238-182.dclient.hispeed.ch is my external ip assigned by the ISP.
But still i don't know this strange HWAddr (00:09:7b:8d:98:70).

All the clients (including my firewall) within the highspeed network
have the same netmask. The IP's are received by DHCP broadcasts.

I have setup iptables, that's why i am wondering about these packets.

These packets are not logged by tcpdump from
80-219-238-182.dclient.hispeed.ch but from 127.0.0.1.

It is confusing as i already said.
.



Relevant Pages

  • Re: Ethernet issue: works one way but not another
    ... packets transmitted, 5 packets received, 0% packet loss ... (This is when connected directly to internet through ... FBSD, I have been working with BSDI at the isp I work for for the last ... As for my network topology, I have an internal network that goes ...
    (freebsd-questions)
  • Re: Update: UDP 770 Potential Worm
    ... > the network immediately after the 'attack', ... were no packets indicating some form of replication. ... I noticed that the UDP ... > of the UDP datagrams is the IP address of the proxy? ...
    (Incidents)
  • Re: IDSIPS that can handle one Gig
    ... especially with 64-byte UDP packets. ... There are plenty of network IPS's ... IDS/IPS devices through use of fragments. ... Find out quickly and easily by testing it with real-world attacks from ...
    (Focus-IDS)
  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)
  • RE: Mapping Class A network ( any easy trick?)
    ... and wondering how I can map the network ... packets per second rate to ask for. ... This will read the payloads.conf file which may have multiple payloads ... per port. ...
    (Pen-Test)