Re: A bit strange ARP queries
"Samuel R. Baskinger" <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Organization | Lumeta Corporation |
| Message-ID | <[email protected]> |
> Eygene A. Ryabinkin wrote: > > > Good day! > > > > Has anyone seen such ARP packets? I am a bit curious, because we > > have no strange hardware that will set the target hardware address > > in the who-has ARP packet. Are there any attacks that using such > > packets? ----- 15:29:59.908901 arp who-has the-host-in-question > > (4:c0:40:1:e0:df) tell the-requester > > 15:30:00.911228 arp who-has the-host-in-question (57:43:50:10:40:0) > > tell the-requester > > 15:30:01.912045 arp who-has <snip> > > ----- 'the-host-in-question' and 'the-requester' are, of course, IP > > addresses. I've seen a few network tools use this method as a sort of Level-2 ping. If you find the cuperit I'd be interested in what software its running. Sam