Re: smurfing
Samuel Gordon-Stewart <smoothwallsamuel-/[email protected]> Sat, 16 Oct 2004 17:54:55 -0700 (PDT)
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <[email protected]> |
--- Pietro Leone <[email protected]> wrote: > I saw, but, I never ping-ed such address, so why > this entries into my > log files? I know that smootwall protects my network > from the outside, > but what this log means? I suppose there is a > program that try to ping > that address. How can I discover the program that > create this traffic? > After this, probably I'll configure my smoothie to > limit the outgoing > traffic too. The address mentioned is not valid on the www, it is specially reserved as per RFC 3171 http://www.faqs.org/rfcs/rfc3171.html and RFC 2365 http://www.faqs.org/rfcs/rfc2365.html All I can assume is that TCP/IP on a computer on green had a reason to send to this address, and as it is not a legitimate address, it was broadcasted to all machines on green (hence the NTOP server seeing it). It does not appear to be harmful, nor does it appear to be capable of getting out onto the internet, afaik this is just TCP/IP noise. >I'm sorry, I wrote you privately instead of writing to Smoothwall mailing-list. no probs :) samuel ===== I must be really old in dog years! Listen to my lovely music www.thefunkyasylum.com/notnice.mp3 Protect your network www.smoothwall.org _______________________________ Do you Yahoo!? Express yourself with Y! Messenger! Free. Download now. http://messenger.yahoo.com _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall