Re: Strange echo requests from 127.0.0.1 apparently to root nameservers
Steve Williamson <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
A utility from Foundstone, fport (www.foundstone.com -> resources ->free tools) may help you find the program generating the traffic. It maps port activity to a running application. hth Steve Terje Trane wrote: >I tried to troubleshoot a PC that all of a sudden would connect but not >route traffic to a remote site by VPN and started Ethereal to see if I could >see where the packets were going. > >To my surprise I can see a dozen ICMP echo request packets per second sent >from 127.0.0.1. Every other is to my internal DNS-servers, and the rest >(except for a few) to *.root-servers.net and *.gtld-servers.net. > >My thought was that this is malware scanning or trying a DoS on the DNS, >though AV is up to date and running. However, the firewall technician says >he cannot see this traffic at the firewall. I tried using tcpdump on an >other machine on the same hub and cannot see this traffic, so I guess it >must be local? > >By looking at the MAC-addresses i see that all packets are from >08:00:2b:00:dc:dc which is not the MAC address of the local PC and completly >unknown to me, and they are sent to 08:00:2b:00:01:02 which is also unknown. >08:00:2b is the vendor code for DEC and we have no DEC equipment here. > >I tried killing the processes I don't know on this PC, but not all will die. >Is there any way in Windows I can see what process is generating what TCP/IP >traffic? > >And most important: What can this be? > > >_______________________________________________ >Intrusions mailing list >[email protected] >http://www.dshield.org/mailman/listinfo/intrusions > > > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions