Re: smurfing

Samuel Gordon-Stewart <smoothwallsamuel-/[email protected]> Sat, 16 Oct 2004 17:54:55 -0700 (PDT)
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <[email protected]>
--- Pietro Leone <[email protected]> wrote:
> I saw, but, I never ping-ed such address, so why
> this entries into my 
> log files? I know that smootwall protects my network
> from the outside, 
> but what this log means? I suppose there is a
> program that try to ping 
> that address. How can I discover the program that
> create this traffic? 
> After this, probably I'll configure my smoothie to
> limit the outgoing 
> traffic too.
The address mentioned is not valid on the www, it is
specially reserved as per RFC 3171
http://www.faqs.org/rfcs/rfc3171.html and RFC 2365
http://www.faqs.org/rfcs/rfc2365.html

All I can assume is that TCP/IP on a computer on green
had a reason to send to this address, and as it is not
a legitimate address, it was broadcasted to all
machines on green (hence the NTOP server seeing it).

It does not appear to be harmful, nor does it appear
to be capable of getting out onto the internet, afaik
this is just TCP/IP noise.

>I'm sorry, I wrote you privately instead of writing
to Smoothwall mailing-list.

no probs :)

samuel

=====
I must be really old in dog years!
Listen to my lovely music www.thefunkyasylum.com/notnice.mp3
Protect your network www.smoothwall.org


		
_______________________________
Do you Yahoo!?
Express yourself with Y! Messenger! Free. Download now. 
http://messenger.yahoo.com
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall